Title : NetBSD Security Update Fixes PPPoE Invalid Memory Access Issue VUPEN ID : VUPEN/ADV-2008-2435 CVE ID : CVE-2008-3584 CWE ID : CWE-126
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-25
Technical Description
A vulnerability has been identified in NetBSD, which could be exploited by attackers to cause a denial of service or potentially compromise a vulnerable system. This issue is caused by an error in range checking when handling packets while establishing PPPoE connections, which could allow a malicious packet to cause the kernel to access memory outside of the allocated buffer, leading to a crash or potentially arbitrary code execution.