NetBSD-SA2009-001Vendor advisory
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-001.txt.asc CVE-2009-0687
OpenBSD 4.5 - IP datagrams Remote Denial of Service
Record summary
CVE-2009-0687 has a selected CVSS score of 7.8; EIP currently links 3 catalogued exploits.
Description
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBOpenBSD 4.5 - IP datagrams Remote Denial of ServiceExploitDB exploitby RembrandtNot analyzed1 file
ExploitDBOpenBSD 4.5 - IP datagram Null Pointer Deref Denial of ServiceExploitDB exploitby nonrootNot analyzed1 file
ExploitDBMultiple Vendor - PF Null Pointer DereferenceExploitDB exploitby RembrandtNot analyzed1 file
References
12helith.net
http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt [4.3] 013: RELIABILITY FIX: April 11, 2009Vendor advisory
http://www.openbsd.org/errata43.html [4.4] 013: RELIABILITY FIX: April 11, 2009Vendor advisory
http://www.openbsd.org/errata44.html [4.5] 002: RELIABILITY FIX: April 11, 2009Vendor advisory
http://www.openbsd.org/errata45.html 53608vdb entry
http://www.osvdb.org/53608 20090413 OpenBSD 4.3 up to OpenBSD-current: PF null pointer dereference - remote DoS (kernel panic)mailing list
http://www.securityfocus.com/archive/1/502634 ADV-2009-1015vdb entry
http://www.vupen.com/english/advisories/2009/1015 openbsd-packetfilter-dos(49837)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/49837 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0687 8406exploit
https://www.exploit-db.com/exploits/8406 8581exploit
https://www.exploit-db.com/exploits/8581