CVE-2008-0177

Kame Ipcomp - Denial of Service

Title source: rule

Description

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mu-b · cdosmultiple
https://www.exploit-db.com/exploits/5191

Scores

EPSS 0.5446
EPSS Percentile 98.0%

Details

Status published
Products (1)
kame/ipcomp
Published Feb 07, 2008
Tracked Since Feb 18, 2026