The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ipcomp | Kame | * | * |
| Kfreebsd-5 | Ubuntu | dapper | * |
| Kfreebsd-5 | Ubuntu | edgy | * |
| Kfreebsd-5 | Ubuntu | feisty | * |
| Kfreebsd-5 | Ubuntu | gutsy | * |
| Kfreebsd-5 | Ubuntu | hardy | * |
| Kfreebsd-5 | Ubuntu | intrepid | * |
| Kfreebsd-5 | Ubuntu | upstream | * |