Executive brief
A vulnerability in the networking component of BSD-based operating systems allows remote attackers to bypass security controls and impersonate trusted connections. By exploiting how the system handles specifically routed network traffic, an attacker can trick the system into accepting unauthorized data or bypassing firewall-like restrictions. This could lead to unauthorized access to services or the ability to intercept sensitive communications.
Technical details
The vulnerability exists within the kernel function 'ip_dooptions()' in 4.4BSD-based kernels. The 'dosourceroute' sysctl variable was incorrectly implemented, only preventing the forwarding of source-routed packets rather than their local delivery. Additionally, the 'forwarding' variable was not checked within the source-routing logic, allowing packets to be forwarded even when global IP forwarding was disabled. An attacker can use IP source routing to direct TCP responses back to their own machine, allowing them to predict sequence numbers and complete a three-way handshake to spoof a connection from a trusted IP address. Patches were released for OpenBSD and FreeBSD to enforce these checks at the start of packet processing.
Affected products
- OpenBSD Project OpenBSD 2.2 and earlier
- FreeBSD Project FreeBSD 2.2.5 and earlier
Timeline
- 1998-02-01: advisory: NVD Published Date
- 1998-02-15: disclosed: OpenBSD Security Advisory released