|
Vulnerability Report: NetBSD 1.x
|
This vulnerability report for NetBSD 1.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.
If you have information about a new or an existing vulnerability in NetBSD 1.x then you are more than welcome to contact us.
|
|
|
|
|
Vendor, Links, and Unpatched Vulnerabilities
|
|
|
|
53 Secunia Advisories in 2003-2009
|
Secunia has issued a total of 53 Secunia advisories in 2003-2009 for NetBSD 1.x. Currently, 11% (6 out of 53) are marked as unpatched with the most severe being rated Highly critical 
More information about the specific Secunia advisories affecting NetBSD 1.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.
|
|
|
|
|
|
Release Date: 2006-04-13 |
Secunia Advisory ID: SA19615 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: A vulnerability has been reported in NetBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2006-04-13 |
Secunia Advisory ID: SA19616 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: A vulnerability has been reported in NetBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2006-04-13 |
Secunia Advisory ID: SA19585 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass
|
Where: From remote |
|
Short Description: A security issue has been reported in NetBSD, which can weaken certain security features. [Read More]
|
|
|
|
|
|
Release Date: 2006-03-30 |
Secunia Advisory ID: SA19464 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: Local system |
|
Short Description: A vulnerability has been reported in NetBSD, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2006-03-30 |
Secunia Advisory ID: SA19463 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has acknowledged a vulnerability in racoon, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2006-03-30 |
Secunia Advisory ID: SA19465 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: Local system |
|
Short Description: A security issue has been reported in NetBSD, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2006-03-30 |
Secunia Advisory ID: SA19466 |
Solution Status: Unpatched |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has acknowledged a vulnerability in sendmail, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2006-01-10 |
Secunia Advisory ID: SA18388 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: Local system |
|
Short Description: A vulnerability has been reported in NetBSD, which can be exploited by malicious, local users to disclose potentially sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2005-11-02 |
Secunia Advisory ID: SA17389 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Privilege escalation DoS System access
|
Where: From remote |
|
Short Description: Some vulnerabilities have been reported in NetBSD, which can be exploited by malicious, local users to gain escalated privileges, or by malicious users to cause a DoS (Denial of Service) and compromise a vulnerable system, or by malicious people to bypass certain security restrictions and compromise a user's system. [Read More]
|
|
|
|
|
|
Release Date: 2005-07-01 |
Secunia Advisory ID: SA15874 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: A vulnerability has been reported in NetBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-12-17 |
Secunia Advisory ID: SA13501 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation DoS
|
Where: Local system |
|
Short Description: Evgeny Demidov has reported some vulnerabilities in NetBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-08-18 |
Secunia Advisory ID: SA12318 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation System access
|
Where: From remote |
|
Short Description: NetBSD has issued an update for ftpd. This fixes some vulnerabilities, which potentially can be exploited by malicious users to gain escalated privileges or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-06-12 |
Secunia Advisory ID: SA11847 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: Evgeny Demidov has reported a vulnerability in NetBSD, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-06-04 |
Secunia Advisory ID: SA11767 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued patches for cvs. These fix a vulnerability, which can be exploited by malicious users to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-22 |
Secunia Advisory ID: SA11462 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Manipulation of data DoS
|
Where: From remote |
|
Short Description: NetBSD has acknowledged a vulnerability, which can be exploited by malicious people to reset established TCP connections on a vulnerable device and potentially inject data into a TCP stream. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-22 |
Secunia Advisory ID: SA11459 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has issued updated versions. These fix two vulnerabilities in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-02-19 |
Secunia Advisory ID: SA10926 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has fixed a vulnerability in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-02-19 |
Secunia Advisory ID: SA10924 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Manipulation of data DoS
|
Where: From remote |
|
Short Description: NetBSD has fixed a vulnerability in racoon IKE daemon, which can be exploited by malicious people to cause a DoS (Denial of Service) on users' connections. [Read More]
|
|
|
|
|
|
Release Date: 2004-02-19 |
Secunia Advisory ID: SA10928 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has fixed a vulnerability in the IPv6 traffic handling, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-02-06 |
Secunia Advisory ID: SA10806 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Exposure of sensitive information Privilege escalation
|
Where: Local system |
|
Short Description: Joost Pol has discovered a vulnerability in BSD, allowing malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-12-17 |
Secunia Advisory ID: SA10450 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From local network |
|
Short Description: NetBSD has issued updated packages for bind. These fix a vulnerability, which can be exploited by malicious people to poison the DNS cache with negative entries. [Read More]
|
|
|
|
|
|
Release Date: 2003-10-10 |
Secunia Advisory ID: SA9986 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: NetBSD has issued an update for OpenSSL. This fixes various vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially gain system access. [Read More]
|
|
|
|
|
|
Release Date: 2003-10-10 |
Secunia Advisory ID: SA9987 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued an update for sendmail. This fixes a vulnerability, which possibly could allow malicious people to gain system access. [Read More]
|
|
|
|
|
|
Release Date: 2003-10-10 |
Secunia Advisory ID: SA9988 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation System access
|
Where: From local network |
|
Short Description: NetBSD has issued an update for XFree86. This fixes some vulnerabilities, which potentially can be exploited by malicious users to escalate their privileges on a vulnerable system or compromise it. [Read More]
|
|
|
|
|
|
Release Date: 2003-09-18 |
Secunia Advisory ID: SA9770 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Exposure of sensitive information DoS
|
Where: Local system |
|
Short Description: Different problems have been identified in the kernel sysctl code, which can lead to exposure of sensitive information or cause a Denial of Service. [Read More]
|
|
|
|
|
|
Release Date: 2003-09-18 |
Secunia Advisory ID: SA9769 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Exposure of sensitive information
|
Where: Local system |
|
Short Description: An information disclosure vulnerability has been identified in NetBSD, which can be exploited by malicious, local users to gain knowledge of content in kernel memory. [Read More]
|
|
|
|
|
|
Release Date: 2003-09-18 |
Secunia Advisory ID: SA9771 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: NetBSD has issued an update for sshd. These fix a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-08-06 |
Secunia Advisory ID: SA9452 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: A vulnerability has been identified in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-08-05 |
Secunia Advisory ID: SA9446 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation DoS System access
|
Where: From remote |
|
Short Description: A vulnerability has been identified in NetBSD, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system or compromise it. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-07 |
Secunia Advisory ID: SA8533 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From local network |
|
Short Description: Samba is vulnerable to a buffer overflow, which can be exploited by anonymous users. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-07 |
Secunia Advisory ID: SA8523 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued updated packages for sendmail. These fix a vulnerability in the address parsing, which potentially can be exploited to compromise a vulnerable mail server. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-07 |
Secunia Advisory ID: SA8519 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Spoofing Security Bypass
|
Where: From remote |
|
Short Description: NetBSD has issued updated packages for Kerberos to address a cryptographic weakness. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-27 |
Secunia Advisory ID: SA8424 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Exposure of system information
|
Where: From remote |
|
Short Description: NetBSD has issued updates for openssl. A vulnerability has been discovered allowing malicious people to retrieve the premaster-secret. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-27 |
Secunia Advisory ID: SA8423 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Exposure of system information
|
Where: From remote |
|
Short Description: NetBSD has released an update for openssl. This eliminates an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of the RSA secret. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-27 |
Secunia Advisory ID: SA8428 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From local network |
|
Short Description: NetBSD has issued updates for libc. A vulnerability has been discovered allowing malicious users to cause an integer overflow, which could lead to a Denial of Service and possibly also execution of arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-17 |
Secunia Advisory ID: SA8299 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From local network |
|
Short Description: A vulnerability has been identified in Samba, which can be exploited by a malicious person to compromise a vulnerable server. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-13 |
Secunia Advisory ID: SA8286 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: NetBSD has released updates for the utility "file". These fix a vulnerability exploitable by malicious, local users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-04 |
Secunia Advisory ID: SA8203 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: From remote |
|
Short Description: NetBSD has released updates for openssl. These eliminate an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of a used plaintext block in a SSL/TLS session. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-04 |
Secunia Advisory ID: SA8202 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued updates for sendmail. Sendmail has been found vulnerable to an issue that could lead to remote root compromise. The problem is with parsing of certain headers. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-20 |
Secunia Advisory ID: SA7557 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued updates to the three recent BIND holes, one allowing attackers system access from remote. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-20 |
Secunia Advisory ID: SA7559 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has issued updated to ftpd. ftpd does not comply with RFC959, when a filename is specified with a "\n[0-9]" it may corrupt the state tables of firewalls. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-20 |
Secunia Advisory ID: SA7558 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has released updates to libc because part of the resolver code suffers a buffer overrun. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-05 |
Secunia Advisory ID: SA7444 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Security Bypass
|
Where: From remote |
|
Short Description: The FTP Proxy module which is part of IPFilter does properly keep track of state of FTP commands and responses. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-24 |
Secunia Advisory ID: SA7379 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: The game trek contains a locally exploitable buffer overflow, allowing local users to gain privileges of the "games" group, this allows a malicious user to alter highscore files and more. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-22 |
Secunia Advisory ID: SA7360 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has issued updates to address the IPsec ESP vulnerability. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-22 |
Secunia Advisory ID: SA7359 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: The kadmind server which is part of heimdal kerberos, contains a remotely expoitable buffer overflow. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-08 |
Secunia Advisory ID: SA7250 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: NetBSD has issued packages fixing the vulnerability allowing users to gain privileges. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-08 |
Secunia Advisory ID: SA7249 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has issued updates to the vulnerability in pic, it is remotely exploitable if your have configured lpd to accept remote printing. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-08 |
Secunia Advisory ID: SA7253 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: NetBSD has released updates to fix the resolver issue. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-08 |
Secunia Advisory ID: SA7252 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: It is possible to gain privileges to group 'games' allowing local users to edit score files and more. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-08 |
Secunia Advisory ID: SA7251 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: NetBSD has released updates to fix possible local root vulnerability in talkd. [Read More]
|
|
|
|
|
|
Release Date: 2002-09-23 |
Secunia Advisory ID: SA7142 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: [Read More]
|
|
|
|
|
|
Release Date: 2002-09-17 |
Secunia Advisory ID: SA7114 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: NetBSD has released patches and updates to a number of "older" issues, which previously has been addressed by CERT and other vendors. [Read More]
|
|
|