Multiple BSD OSs contain a flaw that may allow a malicious attacker to bypass firewall rulesets. The issue is triggered when a packet is sent with a unicast link-layer address that contains an IP broadcast address. It is possible that the flaw may allow a TCP connection to a broadcast address resulting in a loss of integrity.
Classification
Location:
Local Access Required,
Remote / Network Access
Attack Type:
Infrastructure
Impact:
Loss of Integrity
Disclosure:
OSVDB Verified
Solution
Upgrade to IRIX version 6.5.17 or higher, as it has been reported to fix this vulnerability. In addition, Apple, FreeBSD, NetBSD and OpenBSD have released patches for some older versions.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.