Lucene search

K
cve[email protected]CVE-2008-0177
HistoryFeb 07, 2008 - 10:00 p.m.

CVE-2008-0177

2008-02-0722:00:00
web.nvd.nist.gov
26
cve-2008-0177
ipcomp6_input
sys/netinet6/ipcomp_input.c
kame project
denial of service
system crash
ipv6 packet
ipcomp header

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.2 Medium

AI Score

Confidence

Low

0.47 Medium

EPSS

Percentile

97.5%

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Affected configurations

NVD
Node
kameipcomp
CPENameOperatorVersion
kame:ipcompkame ipcompeq*

References

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.2 Medium

AI Score

Confidence

Low

0.47 Medium

EPSS

Percentile

97.5%