PT-2009-3317 · Openbsd+3 · Openbsd+3
Rembrandt
·
Published
2009-08-11
·
Updated
2017-09-29
·
CVE-2009-0687
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenBSD versions 4.2 through 4.5
NetBSD version 5.0 before RC3
MirOS version 10 and earlier
MidnightBSD version 0.3-current
Description
The issue allows remote attackers to cause a denial of service via crafted IP packets, triggering a NULL pointer dereference during translation. This is related to an IPv4 packet with an ICMPv6 payload.
Recommendations
For OpenBSD versions 4.2 through 4.5, update to a version outside of this range to resolve the issue.
For NetBSD version 5.0 before RC3, update to RC3 or later to resolve the issue.
For MirOS version 10 and earlier, update to a version later than 10 to resolve the issue.
For MidnightBSD version 0.3-current, consider restricting access to the
pf test rule function until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Midnightbsd
Miros
Netbsd
Openbsd