← Back

CVE-2008-1335

nvd nist
Published: Mar 13, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.

Affected (14)

2 products
Netbsd
Netbsd Current
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Netbsd
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0
Version 2.1.1
Version 2.1
Version 3.0.1
Version 3.0.2
Version 3.0
Version 3.1
Version 3.1 rc1
Version 3.1 rc3
Up to 20071027

References (8)

ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-002.txt.asc (unsafe URL)
Source: cve@mitre.org
ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-002.txt.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.