CVE-2006-1797: Null Pointer Dereference
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1797?
CVE-2006-1797 is classified as a denial of service vulnerability due to a system crash from a NULL pointer dereference.
How do I fix CVE-2006-1797?
To fix CVE-2006-1797, it is recommended to upgrade to the latest version of NetBSD that patches this vulnerability.
Who is affected by CVE-2006-1797?
CVE-2006-1797 affects local users of NetBSD versions 1.6, 1.6.1, 1.6.2, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.1, and 3.0.
Can CVE-2006-1797 be exploited remotely?
CVE-2006-1797 cannot be exploited remotely as it requires local user access to the system.
What conditions lead to the exploitation of CVE-2006-1797?
The exploitation of CVE-2006-1797 occurs when a local user attempts to use the SIOCGIFALIAS ioctl on a non-existent alias.