First published: Thu Feb 02 2006(Updated: )
Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =5.4 | |
FreeBSD Kernel | =5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0433 is classified as a denial of service vulnerability.
To mitigate CVE-2006-0433, upgrade your FreeBSD system to version 5.5 or later.
CVE-2006-0433 affects FreeBSD versions 5.3 and 5.4.
CVE-2006-0433 enables a denial of service attack that can lead to an infinite loop.
Remote attackers can exploit CVE-2006-0433 to disrupt service.