Overview
A vulnerability in the OpenBSD kernel could allow a remote attacker to execute arbitrary code on a vulnerable system or cause the system to crash.
Description
The OpenBSD kernel contains a flaw in its handling of kernel memory buffers when processing IPv6 packets. This flaw results in a memory corruption vulnerability that allows a remote attacker with the ability to send fragmented ICMPv6 packets to trigger an overflow of mbuf kernel memory structures. The original reporters of this vulnerability, Core Security Technologies, have published a detailed analysis of this vulnerability in CoreLabs Advisory CORE-2007-0219. Systems connected to public IPv6 networks are particularly at risk from this vulnerability. However, since link-local addresses are part of the IPv6 specification and configured by default on Ethernet interfaces, even systems that have not been explicitly configured to use public IPv6 networks are vulnerable to attack from other systems on the same physical network or multicast network. |
Impact
A remote, unauthenticated attacker with the ability to supply a specially crafted fragmented IPv6 packet may be able to execute arbitrary code on a vulnerable system or cause the system to crash. The attacker-supplied code would be executed in the context of the kernel. |
Solution
Apply a patch from the vendor |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://secunia.com/advisories/24490/
- http://www.openbsd.org/errata40.html#m_dup1
- http://www.openbsd.org/errata39.html#m_dup1
- http://www.coresecurity.com/?action=item&id=1703
- http://securitytracker.com/id?1017735
- http://www.securityfocus.com/bid/22901
- http://isc.sans.org/diary.html?storyid=2445
- http://archives.neohapsis.com/archives/bugtraq/2007-03/0158.html
- http://jvn.jp/cert/JVNVU%23986425/index.html
Acknowledgements
This vulnerability was discovered and researched by Alfredo Ortega from Core Security Technologies.
This document was written by Chad R Dougherty.
Other Information
CVE IDs: | CVE-2007-1365 |
Severity Metric: | 16.80 |
Date Public: | 2007-03-12 |
Date First Published: | 2007-03-15 |
Date Last Updated: | 2007-05-03 19:51 UTC |
Document Revision: | 18 |