Apple Mac OS X VPND Remote Denial of Service Vulnerability
BID:26699
Info
Apple Mac OS X VPND Remote Denial of Service Vulnerability
| Bugtraq ID: | 26699 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-6276 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2007 12:00AM |
| Updated: | Jul 02 2008 08:30PM |
| Credit: | mu-b is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Apple Mac OS X Server 10.5.4 Apple Mac OS X 10.5.4 |
Discussion
Apple Mac OS X VPND Remote Denial of Service Vulnerability
Apple Mac OS X is prone to a remote denial-of-service vulnerability because the virtual private network daemon ('vpnd') fails to handle specially crafted network packets.
An attacker can exploit this issue to crash affected computers, denying service to legitimate users.
This issue affects Apple Mac OS X 10.5; other versions may also be affected.
Apple Mac OS X is prone to a remote denial-of-service vulnerability because the virtual private network daemon ('vpnd') fails to handle specially crafted network packets.
An attacker can exploit this issue to crash affected computers, denying service to legitimate users.
This issue affects Apple Mac OS X 10.5; other versions may also be affected.
Exploit / POC
Apple Mac OS X VPND Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Apple Mac OS X VPND Remote Denial of Service Vulnerability
Solution:
The vendor has released an advisory and fixes to address this issue. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has released an advisory and fixes to address this issue. Contact the vendor for details on obtaining the appropriate updates.
References
Apple Mac OS X VPND Remote Denial of Service Vulnerability
References:
References: