CVE-2006-3202: Medium severity NetBSD NetBSD vulnerability

Published Jun 23, 2006
·
Updated

The ip6savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SOTIMESTAMP socket option set, then sending an IPv4 packet through the socket.

Affected Software

5 affected components
NetBSD NetBSD=2.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=2.0.3
NetBSD NetBSD=3.0
NetBSD NetBSD=2.0

Event History

Jun 23, 2006
CVE Published
08:06 PM
Jun 24, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2006-3202?

CVE-2006-3202 is classified as a denial of service vulnerability, which can crash the system.

2

How do I fix CVE-2006-3202?

To fix CVE-2006-3202, upgrade to a version of NetBSD that is not affected, such as versions above 3.0.

3

Who is affected by CVE-2006-3202?

CVE-2006-3202 affects local users running NetBSD versions 2.0 to 3.0 with specific configurations.

4

What causes CVE-2006-3202?

CVE-2006-3202 is caused by the ip6_savecontrol function failing to check for IPv4-mapped sockets before processing IPv6 socket options.

5

Can CVE-2006-3202 be exploited remotely?

CVE-2006-3202 cannot be exploited remotely as it requires local user access to trigger the denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203