CVE Vulnerabilities

CVE-2008-0177

Published: Feb 07, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Affected Software

NameVendorStart VersionEnd Version
IpcompKame**
Kfreebsd-5Ubuntudapper*
Kfreebsd-5Ubuntuedgy*
Kfreebsd-5Ubuntufeisty*
Kfreebsd-5Ubuntugutsy*
Kfreebsd-5Ubuntuhardy*
Kfreebsd-5Ubuntuintrepid*
Kfreebsd-5Ubuntuupstream*

References