CVE-2008-2464

KAME - Denial of Service via Malformed ICMPv6 MLD Query

Title source: llm
STIX 2.1

Description

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31026
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/817940
Vendor Advisory vendor-advisory x_refsource_netbsd
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-011.txt.asc
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1020822

Scores

EPSS 0.0310
EPSS Percentile 87.0%

Details

CWE
CWE-189
Status published
Products (3)
freebsd/freebsd
kame/kame
netbsd/netbsd 4.0
Published Sep 11, 2008
Tracked Since Feb 18, 2026