CVE-2008-0177: High severity kame kame vulnerability
The ipcomp6input function in sys/netinet6/ipcompinput.c in the KAME project before 20071201 does not properly check the return value of the mpulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0177?
CVE-2008-0177 has a severity rating that indicates it can lead to a denial of service due to a system crash.
How do I fix CVE-2008-0177?
To fix CVE-2008-0177, update to a version of the KAME project that is dated 20071201 or later.
What type of attack does CVE-2008-0177 enable?
CVE-2008-0177 enables remote attackers to trigger a denial of service attack through crafted IPv6 packets.
Which software is affected by CVE-2008-0177?
CVE-2008-0177 affects the Kame Ipcomp implementation prior to the update released on 20071201.
What is the impact of exploiting CVE-2008-0177?
Exploitation of CVE-2008-0177 can lead to a system crash, impacting availability of the affected service.