Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
BID:31529
Info
Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
| Bugtraq ID: | 31529 |
| Class: | Design Error |
| CVE: |
CVE-2008-2476 CVE-2008-4404 CVE-2009-0418 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2008 12:00AM |
| Updated: | Mar 19 2015 09:41AM |
| Credit: | David Miles reported this issue. |
| Vulnerable: |
Wind River Systems VxWorks 6.4 Wind River Systems VxWorks 5 OpenBSD OpenBSD 4.4 OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 NetBSD NetBSD 3.0.2 NetBSD NetBSD 3.0.1 NetBSD NetBSD Current NetBSD NetBSD 4.0 NetBSD NetBSD 3.1_RC3 NetBSD NetBSD 3.1 NetBSD NetBSD 3,1_RC1 Navision Financials Server 3.0 MidnightBSD MidnightBSD 0.2.1 MidnightBSD MidnightBSD 0.1.1 MidnightBSD MidnightBSD 0.3 MidnightBSD MidnightBSD 0.1 Juniper Networks WXC Series 0 Juniper Networks WX Series 0 Juniper Networks Session and Resource Control Appliance 2.0 Juniper Networks Session and Resource Control Appliance 1.0 Juniper Networks Secure Access 700 0 Juniper Networks Secure Access 6000 SP 6000 Juniper Networks Secure Access 6000 (NetScreen-SA 5000 Series) 0 Juniper Networks Secure Access 4000 (NetScreen-SA 3000 Series) 0 Juniper Networks Secure Access 2000 0 Juniper Networks IVE OS 6.0 Juniper Networks IVE OS 5.0 Juniper Networks IVE OS 4.0 Juniper Networks IVE OS 3.0 Juniper Networks IVE OS 2.0 Juniper Networks IVE OS 1.0 Juniper Networks Infranet Controller 6000 Juniper Networks Infranet Controller 4000 Juniper Networks IDP 4.0 Juniper Networks DXOS 5.0 IBM z/OS HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX 11i v3 HP HP-UX 11i v2 HP HP-UX 11i v1 FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 7.1 -RELEASE-p1 FreeBSD FreeBSD 7.0-STABLE FreeBSD FreeBSD 7.0-RELEASE FreeBSD FreeBSD 7.0 BETA4 FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 -PRERELEASE FreeBSD FreeBSD 7.0 FreeBSD FreeBSD 6.3 -RELENG FreeBSD FreeBSD 6.3 FreeBSD FreeBSD 6.2 -STABLE FreeBSD FreeBSD 6.2 -RELENG FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE-p10 FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 6.0 -RELEASE-p5 Force10 Networks FTOS 7.7.1 1 Avaya Proactive Contact 3.0 Apple AirPort Extreme Base Station 0 Apple AirPort Express Firmware 6.3 Apple AirPort Express Firmware 6.1 Apple AirPort Base Station |
| Not Vulnerable: |
Apple Time Capsule Firmware 7.4.1 Apple AirPort Extreme Base Station with 802.11n Firmware 7.4.1 Apple AirPort Express Base Station with 802.11n Firmware 7.4.1 |
Discussion
Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
Multiple vendors' IPv6 Neighbor Discovery Protocol (NDP) implementations are prone to a security vulnerability.
Exploiting the issue may allow attackers to intercept network traffic, perform man-in-the-middle attacks, or cause congested links to become overloaded.
Multiple vendors' IPv6 Neighbor Discovery Protocol (NDP) implementations are prone to a security vulnerability.
Exploiting the issue may allow attackers to intercept network traffic, perform man-in-the-middle attacks, or cause congested links to become overloaded.
Exploit / POC
Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
Attackers can exploit this issue using standard, readily available tools.
Attackers can exploit this issue using standard, readily available tools.
Solution / Fix
Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
Solution:
Fixes are available. Please see the references for more information.
OpenBSD OpenBSD 4.3
OpenBSD OpenBSD 4.4
OpenBSD OpenBSD 4.2
Solution:
Fixes are available. Please see the references for more information.
OpenBSD OpenBSD 4.3
-
OpenBSD 006_ndp.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/006_ndp.patch
OpenBSD OpenBSD 4.4
-
OpenBSD 001_ndp.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/001_ndp.patch
OpenBSD OpenBSD 4.2
-
OpenBSD 015_ndp.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/015_ndp.patch
References
Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability
References:
References:
- IPv6 Neighbor Discovery (ND) Trust Models and Threats (The Internet Engineering Task Force)
- MidnightBSD Home Page (MidnightBSD)
- Neighbor Discovery for IP Version 6 (IPv6) (The Internet Engineering Task Force)
- Vulnerability Note VU#472363 IPv6 implementations insecurely update Forward Info (US-CERT)
- 006: SECURITY FIX: October 2, 2008 (OpenBSD)
- 015: SECURITY FIX: October 2, 2008 (OpenBSD)
- About the security content of Time Capsule and AirPort Base Station (802.11n*) F (Apple)
- ASA-2009-059 - HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthoriz (Avaya)
- HPSBUX02407 SSRT080107 rev.1 - HP-UX Running IPv6, Remote Denial of Service (DoS (HP)
- Juniper Networks, Inc. Information for VU#472363 (US-CERT)
- November 2, 2008: The Neighbor Discovery Protocol (ndp) did not correctly verify (OpenBSD)
- VU#472363 - IPv6 routing table vulnerability (US-CERT)