Lucene search

K
cve[email protected]CVE-2006-6653
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2006-6653

2022-10-0316:21:24
CWE-20
web.nvd.nist.gov
15
netbsd
cve-2006-6653
denial of service
socket
vulnerability

1.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may result in the socket never being closed (aka “a dangling socket”).

Affected configurations

NVD
Node
netbsdnetbsdMatch2.0
OR
netbsdnetbsdMatch3.0
OR
netbsdnetbsdMatch3.0.1
OR
netbsdnetbsdMatchcurrent

1.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2006-6653