PT-2008-4914 · Netbsd Foundation+1 · Netbsd+1

Bjoern A. Zeeb

+1

·

Published

2008-09-05

·

Updated

2017-08-08

·

CVE-2008-3530

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 6.3 through 7.1 NetBSD versions 3.0 through 4.0
Description The issue is related to the improper checking of the proposed new MTU in an ICMPv6 Packet Too Big Message. This allows remote attackers to cause a denial of service, resulting in a system panic, via a crafted Packet Too Big Message.
Recommendations For FreeBSD versions 6.3 through 7.1, update to a version that properly checks the proposed new MTU in an ICMPv6 Packet Too Big Message. For NetBSD versions 3.0 through 4.0, update to a version that properly checks the proposed new MTU in an ICMPv6 Packet Too Big Message.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3530

Affected Products

Freebsd
Netbsd