The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may result in the socket never being closed (aka "a dangling socket").
2006-12-20T02:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 1.7 (LOW)
AV:L/AC:L/Au:S/C:N/I:N/A:P
3.1
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netbsd | netbsd | 2.0 | Yes |
Operating System | netbsd | netbsd | 3.0 | Yes |
Operating System | netbsd | netbsd | 3.0.1 | Yes |
Operating System | netbsd | netbsd | current | Yes |