Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2464

Overview

Vulnerability Score 7.1 7.1
CVE Id CVE-2008-2464
Last Modified 11 Sep 2008 12:00:00
Published 10 Sep 2008 09:10:39
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2464

Summary

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.

Vulnerable Systems

Operating System

  • Freebsd

  • Netbsd 4.0

Application

  • Kame


References

CERT-VN - VU#817940

BID - 31026

CONFIRM - http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet6/mld6.c.diff?r1=1.34;r2=1.35;f=h

CONFIRM - http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet6/mld6.c

SECTRACK - 1020822

NETBSD - NetBSD-SA2008-011

CONFIRM - http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/mld6.c.diff?r1=1.46&r2=1.47&f=h

CONFIRM - http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/mld6.c

MISC - http://cert.fi/haavoittuvuudet/2008/advisory-netbsd.html


Last Updated: 27 May 2016 10:47:52