Vulnerability Description
The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows remote attackers to bypass intended access restrictions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 5.3 |
References
- http://secunia.com/advisories/20389PatchVendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-06:15.ypserv.ascPatchVendor Advisory
- http://securitytracker.com/id?1016193
- http://www.osvdb.org/25852
- http://www.securityfocus.com/bid/18204Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26792
- http://secunia.com/advisories/20389PatchVendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-06:15.ypserv.ascPatchVendor Advisory
- http://securitytracker.com/id?1016193
- http://www.osvdb.org/25852
- http://www.securityfocus.com/bid/18204Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26792
FAQ
What is CVE-2006-2655?
CVE-2006-2655 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows remote attackers to bypass intended access restrict...
How severe is CVE-2006-2655?
CVE-2006-2655 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-2655?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.