SB2019051522 - Input validation error in FreeBSD



SB2019051522 - Input validation error in FreeBSD

Published: May 15, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019051522
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-5597)

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter.


Remediation

Install update from vendor's website.