Description
sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.
References (15)
Core 15
Core References
Vendor Advisory vendor-advisory
x_refsource_netbsd
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/31745
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3549
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3467
Patch vendor-advisory
x_refsource_freebsd
http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35074
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1021111
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44908
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31004
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-133A.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1297
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1020820
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32401
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0633
Scores
EPSS
0.0584
EPSS Percentile
90.6%
Details
CWE
CWE-20
Status
published
Products (3)
freebsd/freebsd
6.3
freebsd/freebsd
7.0
freebsd/freebsd
7.1
Published
Sep 05, 2008
Tracked Since
Feb 18, 2026