Record summary

CVE-2009-0687 has a selected CVSS score of 7.8; EIP currently links 3 catalogued exploits.

Description

The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBOpenBSD 4.5 - IP datagrams Remote Denial of ServiceExploitDB exploitby RembrandtNot analyzed1 file
ExploitDB

PoC details
ExploitDBOpenBSD 4.5 - IP datagram Null Pointer Deref Denial of ServiceExploitDB exploitby nonrootNot analyzed1 file
ExploitDB

PoC details
ExploitDBMultiple Vendor - PF Null Pointer DereferenceExploitDB exploitby RembrandtNot analyzed1 file
ExploitDB

PoC details

References

12