CVE Vulnerabilities

CVE-2008-0177

Published: Feb 07, 2008 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Affected Software

Name Vendor Start Version End Version
Ipcomp Kame * *
Kfreebsd-5 Ubuntu dapper *
Kfreebsd-5 Ubuntu edgy *
Kfreebsd-5 Ubuntu feisty *
Kfreebsd-5 Ubuntu gutsy *
Kfreebsd-5 Ubuntu hardy *
Kfreebsd-5 Ubuntu intrepid *
Kfreebsd-5 Ubuntu upstream *

References