PT-2007-2760 · Openbsd · Openbsd
Published
2007-03-10
·
Updated
2016-10-18
·
CVE-2007-1365
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenBSD versions 3.9 through 4.0
Description
The issue is related to a buffer overflow in the kern/uipc mbuf2.c file, which allows remote attackers to execute arbitrary code via fragmented IPv6 packets. This is due to incorrect mbuf handling for ICMP6 packets.
Recommendations
For OpenBSD versions 3.9 through 4.0, update to a version that includes the fix for the buffer overflow issue in kern/uipc mbuf2.c to prevent remote code execution via fragmented IPv6 packets.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbsd