The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ipcomp | Kame | * | * |
Kfreebsd-5 | Ubuntu | dapper | * |
Kfreebsd-5 | Ubuntu | edgy | * |
Kfreebsd-5 | Ubuntu | feisty | * |
Kfreebsd-5 | Ubuntu | gutsy | * |
Kfreebsd-5 | Ubuntu | hardy | * |
Kfreebsd-5 | Ubuntu | intrepid | * |
Kfreebsd-5 | Ubuntu | upstream | * |