CVE-2008-0177

NONE EPSS 96.4%
Published Feb 7, 200818y ago · Modified Jun 16, 20262w ago
Find Similar
Published Feb 7, 2008 18y ago
Last Modified Jun 16, 2026 2w ago

Description

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Threat Intelligence

EPSS Exploit Probability
96.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 1

VendorProductVersionRange
kameipcomp*any

References 20

  • cvsweb.netbsd.org http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1
    Vendor Advisory
  • lists.apple.com http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
  • lists.apple.com http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
  • secunia.com http://secunia.com/advisories/28788
    PatchVendor Advisory
  • secunia.com http://secunia.com/advisories/28816
    Vendor Advisory
  • secunia.com http://secunia.com/advisories/28979
  • secunia.com http://secunia.com/advisories/29130
  • secunia.com http://secunia.com/advisories/30430
  • secunia.com http://secunia.com/advisories/31074
  • security.freebsd.org http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc
  • securitytracker.com http://securitytracker.com/id?1019314
  • kame.net http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36%3Br2=1.37
  • kb.cert.org http://www.kb.cert.org/vuls/id/110947
    US Government Resource
  • securityfocus.com http://www.securityfocus.com/bid/27642
    Patch
  • us-cert.gov http://www.us-cert.gov/cas/techalerts/TA08-150A.html
    US Government Resource
  • vupen.com http://www.vupen.com/english/advisories/2008/0441
  • vupen.com http://www.vupen.com/english/advisories/2008/0688
  • vupen.com http://www.vupen.com/english/advisories/2008/1697
  • vupen.com http://www.vupen.com/english/advisories/2008/2094/references
  • exploit-db.com https://www.exploit-db.com/exploits/5191

Remediation