Multiple vendor IPv6 NDP implementation denial of service

multiple-vendor-ndp-dos (45601) The risk level is classified as MediumMedium Risk

Description:

Multiple vendor IPv6 Neighbor Discovery Protocol (NDP) implementations are vulnerable to a denial of service, caused by a failure to validate the origin of Neighbor Discovery messages. By sending a spoofed neighbor solicitation request, a remote attacker with IPv6 connectivity to the targeted system could exploit this vulnerability to intercept traffic or add a false entry to the router's neighbor cache, which could result in a denial of service.

Platforms Affected:

  • Apple, 802.11n 7.4.1
  • Apple, AirPort Express Base Station
  • Apple, AirPort Extreme Base Station
  • Apple, Time Capsule
  • Force10, FTOS
  • FreeBSD, FreeBSD 6.0
  • FreeBSD, FreeBSD 6.3
  • FreeBSD, FreeBSD 6.4
  • FreeBSD, FreeBSD 7.0
  • HP, HP-UX B.11.11
  • HP, HP-UX B.11.23
  • HP, HP-UX B.11.31
  • IBM, zSeries
  • Juniper, JNOS
  • NetBSD, NetBSD 3.0
  • NetBSD, NetBSD 3.1
  • NetBSD, NetBSD 4.0
  • WindRiver, VxWorks 5.x
  • WindRiver, VxWorks 6.x

Remedy:

For FreeBSD:
Refer to FreeBSD-SA-08:10.nd6 for patch, upgrade or suggested workaround information. See References.

For FTOS:
Upgrade to the latest version of FTOS (E7.7.1.1 or later), available from the Force10 Networks Web site. See References.

For other distributions:
Apply the appropriate update for your system. See References.

Consequences:

Denial of Service

References:

Reported:

Oct 02, 2008

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page