7.8
CVSSv2

CVE-2008-0177

Published: 07/02/2008 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project prior to 20071201 does not properly check the return value of the m_pulldown function, which allows remote malicious users to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

Vulnerable Product Search on Vulmon Subscribe to Product

kame ipcomp

Exploits

/* xnu-ipv6-ipcompc * * Copyright (c) 2008 by <mu-b@digit-labsorg> * * Apple MACOS X xnu <= 1228313 ipv6-ipcomp remote kernel DoS POC * by mu-b - Sun 24 Feb 2008 * * - Tested on: Apple MACOS X 1051 (xnu-122802~1/RELEASE_I386) * Apple MACOS X 1052 (xnu-1228313~1/RELEASE_I386) * * ipcomp6_input does not ver ...
Apple Mac OS X xnu versions 1228313 and below ipv6-ipcomp remote kernel denial of service proof of concept exploit ...