OpenBSD IPv6 packet denial of service
| openbsd-ipv6-dos (15044) |
Description:
OpenBSD is vulnerable to a denial of service. A remote attacker could send a specially-crafted IPv6 packet that contains a small MTU (Maximum Transfer Unit) to the vulnerable system and then establish a TCP connection to cause the system to crash.
Platforms Affected:
- NetBSD, NetBSD 1.6
- NetBSD, NetBSD 1.6.1
- NetBSD, NetBSD CURRENT
- OpenBSD, OpenBSD 3.4
Remedy:
Apply the fix for this vulnerability, available from the CVS log for src/sys/netinet6/ip6_output.c Web page. See References.
For NetBSD-current (dated prior to 2004-02-05), 1.5, and 1.6 branch:
Upgrade to the appropriate fixed versions of NetBSD, as listed in NetBSD Security Advisory 2004-002. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Denial of Service
References:
- CVS log for src/sys/netinet6/ip6_output.c Web page, Revision 1.82 at http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c.
- Full-Disclosure Mailing List, Wed Feb 04 2004 - 10:08:53 CST, Remote openbsd crash with ip6, yet still openbsd much better than windows at http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0148.html.
- NetBSD Security Advisory 2004-002, Inconsistent IPv6 path MTU discovery handling at http://mail-index.netbsd.org/netbsd-announce/2004/02/19/0001.html.
- OpenBSD Security Fix: 011, An IPv6 MTU handling problem exists that could be used by an attacker to cause a denial of service attack against hosts with reachable IPv6 TCP ports. at http://www.openbsd.com/errata.html#ip6.
- BID-9577: BSD ICMPV6 Handling Routines Remote Denial Of Service Vulnerability
- CVE-2004-0257: OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.
- OSVDB ID: 3825: Multiple BSD IPv6 Traffic Handling DoS
Reported:
Feb 04, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
