First published: Tue Aug 11 2009(Updated: )
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =4.4 | |
MirOS BSD | <=10 | |
NetBSD NetBSD | =5.0 | |
MidnightBSD | =0.3-current | |
OpenBSD | =4.5 | |
OpenBSD | =4.2 | |
OpenBSD | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0687 is classified as a high severity vulnerability due to its potential to cause denial of service by exploiting a NULL pointer dereference.
CVE-2009-0687 affects OpenBSD versions 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current.
To fix CVE-2009-0687, upgrade to a patched version of OpenBSD, NetBSD, MirOS, or MidnightBSD that addresses this vulnerability.
CVE-2009-0687 enables remote attackers to launch a denial of service attack via crafted IP packets.
CVE-2009-0687 was disclosed in 2009, highlighting a significant vulnerability in the OpenBSD Packet Filter.