CVE-2008-1335: Critical severity netbsd current vulnerability
The ipsec4getulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fastipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1335?
CVE-2008-1335 is classified as a medium severity vulnerability.
How do I fix CVE-2008-1335?
To mitigate CVE-2008-1335, update NetBSD to a version released after 20071028 where the vulnerability is addressed.
What systems are affected by CVE-2008-1335?
CVE-2008-1335 affects NetBSD versions 2.0 through 3.1, including certain release candidates.
Can CVE-2008-1335 be exploited remotely?
Yes, CVE-2008-1335 can be exploited remotely due to its nature of allowing attackers to bypass IPsec policy.
What does CVE-2008-1335 involve?
CVE-2008-1335 involves the ipsec4_get_ulp function which allows packet manipulation based on differing endianness.