KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
BID:27642
Info
KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
| Bugtraq ID: | 27642 |
| Class: | Design Error |
| CVE: |
CVE-2008-0177 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2008 12:00AM |
| Updated: | Jul 11 2008 08:19PM |
| Credit: | Shoichi Sakane reported this issue. |
| Vulnerable: |
NetBSD NetBSD 3.0.2 NetBSD NetBSD 3.0.1 NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 3.1_RC3 NetBSD NetBSD 3.1 NetBSD NetBSD 3.1 NetBSD NetBSD 3,1_RC1 NetBSD NetBSD 2.0.4 Navision Financials Server 3.0 KAME KAME project 0 FreeBSD FreeBSD 5.5 Force10 Networks FTOS 7.6 0 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Force10 Networks FTOS 7.6.1.0 Apple iPod Touch 2.0 Apple iPhone 2.0 |
Discussion
KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
The KAME project is prone to a denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to crash affected computers, denying service to legitimate users.
Operating systems that have IPv6 networking derived from the KAME project's IPv6 implementation may be vulnerable to this issue. Please see the references for a list of vendors that may be affected by this issue.
The KAME project is prone to a denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to crash affected computers, denying service to legitimate users.
Operating systems that have IPv6 networking derived from the KAME project's IPv6 implementation may be vulnerable to this issue. Please see the references for a list of vendors that may be affected by this issue.
Exploit / POC
KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
The following exploit code is avaialble:
Attackers can use readily available network utilities to exploit this issue.
The following exploit code is avaialble:
Solution / Fix
KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
Solution:
A fix is available in the CVS repository. Vendor fixes also available. Please see the references for more information.
Apple Mac OS X Server 10.5
Apple Mac OS X 10.5
Apple Mac OS X 10.5.1
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
A fix is available in the CVS repository. Vendor fixes also available. Please see the references for more information.
Apple Mac OS X Server 10.5
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X 10.5.1
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.1
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5.2
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.2
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
References
KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
References:
References:
- CVS log for src/sys/netinet6/ipcomp_input.c (NetBSD)
- Diffs between KAME revisions (KAME)
- Vendor Homepage (KAME Project)
- Vulnerability Note VU#110947 (US-CERT)
- FreeBSD Security Advisory FreeBSD-SA-08:04.ipsec (FreeBSD Security Advisories
)