CVE-2008-3530

sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.
References
Link Resource
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/31745 Vendor Advisory
http://secunia.com/advisories/32401
http://secunia.com/advisories/35074
http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc Patch
http://support.apple.com/kb/HT3467
http://support.apple.com/kb/HT3549
http://www.securityfocus.com/bid/31004 Patch
http://www.securitytracker.com/id?1020820
http://www.securitytracker.com/id?1021111
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2009/0633
http://www.vupen.com/english/advisories/2009/1297
https://exchange.xforce.ibmcloud.com/vulnerabilities/44908
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/31745 Vendor Advisory
http://secunia.com/advisories/32401
http://secunia.com/advisories/35074
http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc Patch
http://support.apple.com/kb/HT3467
http://support.apple.com/kb/HT3549
http://www.securityfocus.com/bid/31004 Patch
http://www.securitytracker.com/id?1020820
http://www.securitytracker.com/id?1021111
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2009/0633
http://www.vupen.com/english/advisories/2009/1297
https://exchange.xforce.ibmcloud.com/vulnerabilities/44908
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:49

Type Values Removed Values Added
References () ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc - () ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc -
References () http://lists.apple.com/archives/security-announce/2009/May/msg00002.html - () http://lists.apple.com/archives/security-announce/2009/May/msg00002.html -
References () http://secunia.com/advisories/31745 - Vendor Advisory () http://secunia.com/advisories/31745 - Vendor Advisory
References () http://secunia.com/advisories/32401 - () http://secunia.com/advisories/32401 -
References () http://secunia.com/advisories/35074 - () http://secunia.com/advisories/35074 -
References () http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc - Patch () http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc - Patch
References () http://support.apple.com/kb/HT3467 - () http://support.apple.com/kb/HT3467 -
References () http://support.apple.com/kb/HT3549 - () http://support.apple.com/kb/HT3549 -
References () http://www.securityfocus.com/bid/31004 - Patch () http://www.securityfocus.com/bid/31004 - Patch
References () http://www.securitytracker.com/id?1020820 - () http://www.securitytracker.com/id?1020820 -
References () http://www.securitytracker.com/id?1021111 - () http://www.securitytracker.com/id?1021111 -
References () http://www.us-cert.gov/cas/techalerts/TA09-133A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA09-133A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2009/0633 - () http://www.vupen.com/english/advisories/2009/0633 -
References () http://www.vupen.com/english/advisories/2009/1297 - () http://www.vupen.com/english/advisories/2009/1297 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44908 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44908 -

Information

Published : 2008-09-05 16:08

Updated : 2024-11-21 00:49


NVD link : CVE-2008-3530

Mitre link : CVE-2008-3530

CVE.ORG link : CVE-2008-3530


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-20

Improper Input Validation