|
|
|
Vulnerability Note VU#110947
KAME project IPv6 IPComp header denial of service vulnerability
OverviewThe KAME project's IPv6 implementation does not properly process IPv6 packets that contain the IPComp header. If exploited, this vulnerability may allow an attacker to cause a vulnerable system to crash.
I. DescriptionPer RFC 3173:
IP payload compression is a protocol to reduce the size of IP datagrams. This protocol will increase the overall communication performance between a pair of communicating hosts/gateways ("nodes") by compressing the datagrams, provided the nodes have sufficient computation power, through either CPU capacity or a compression coprocessor, and the communication is over slow or congested links.
Systems that have IPv6 networking derived from the KAME project IPv6 implementation may not properly process IPv6 packets that contain an IPComp header. An attacker can exploit this vulnerability by sending an IPv6 packet with a IPComp header to a vulnerable system.
II. ImpactA remote, unauthenticated attacker can cause a vulnerable system to crash.
III. SolutionSee the systems affected section of this document for a partial list of affected vendors. Administrators who compile their kernel from source should see http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37 for more information.
Restrict access
Until updates can be applied, using a packet-filtering firewall to block IPv6 packets that contain the IPComp header may prevent this vulnerability from being exploited by remote attackers.
Systems Affected
| Vendor | Status | Date Updated |
| 3com, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Alcatel | Unknown | 2007-11-30 | 2007-11-30 |
| Apple Computer, Inc. | Vulnerable | 2007-11-30 | 2008-05-29 |
| AT&T | Unknown | 2007-11-30 | 2007-11-30 |
| Avaya, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Avici Systems, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Borderware Technologies | Not Vulnerable | 2007-11-30 | 2008-01-30 |
| Bro | Unknown | 2007-11-30 | 2007-11-30 |
| CentOS | Unknown | 2008-01-21 | 2008-01-21 |
| Charlotte's Web Networks | Unknown | 2007-11-30 | 2007-11-30 |
| Check Point Software Technologies | Unknown | 2007-11-30 | 2007-11-30 |
| Chiaro Networks, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Cisco Systems, Inc. | Not Vulnerable | 2007-11-30 | 2008-02-08 |
| Clavister | Unknown | 2007-11-30 | 2007-11-30 |
| Computer Associates | Not Vulnerable | 2007-11-30 | 2008-02-01 |
| Computer Associates eTrust Security Management | Not Vulnerable | 2007-11-30 | 2008-02-01 |
| Conectiva Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Cray Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| D-Link Systems, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Data Connection, Ltd. | Unknown | 2007-11-30 | 2007-11-30 |
| Debian GNU/Linux | Not Vulnerable | 2007-11-30 | 2008-03-16 |
| EMC Corporation | Unknown | 2007-11-30 | 2007-11-30 |
| Engarde Secure Linux | Unknown | 2007-11-30 | 2007-11-30 |
| Enterasys Networks | Unknown | 2007-11-30 | 2007-11-30 |
| Ericsson | Unknown | 2007-11-30 | 2007-11-30 |
| eSoft, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Extreme Networks | Not Vulnerable | 2007-11-30 | 2009-04-29 |
| F5 Networks, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Fedora Project | Unknown | 2007-11-30 | 2007-11-30 |
| Force10 Networks, Inc. | Vulnerable | 2007-11-30 | 2008-02-06 |
| Fortinet, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Foundry Networks, Inc. | Not Vulnerable | 2007-11-30 | 2008-04-03 |
| FreeBSD, Inc. | Vulnerable | 2007-11-30 | 2008-02-27 |
| Fujitsu | Unknown | 2007-11-30 | 2007-11-30 |
| Gentoo Linux | Unknown | 2007-11-30 | 2007-11-30 |
| Global Technology Associates | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| Hewlett-Packard Company | Unknown | 2007-11-30 | 2007-11-30 |
| Hitachi | Not Vulnerable | 2007-11-30 | 2008-02-01 |
| Hyperchip | Unknown | 2007-11-30 | 2007-11-30 |
| IBM Corporation | Not Vulnerable | 2007-11-30 | 2008-02-06 |
| IBM Corporation (zseries) | Unknown | 2007-11-30 | 2007-11-30 |
| IBM eServer | Unknown | 2007-11-30 | 2007-11-30 |
| Ingrian Networks, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Intel Corporation | Unknown | 2008-01-21 | 2008-02-01 |
| Internet Security Systems, Inc. | Not Vulnerable | 2007-11-30 | 2008-02-06 |
| Intoto | Not Vulnerable | 2007-11-30 | 2008-02-08 |
| IP Filter | Unknown | 2007-11-30 | 2007-11-30 |
| Juniper Networks, Inc. | Vulnerable | 2007-11-30 | 2008-02-07 |
| KAME Project | Vulnerable | 2008-02-05 | 2008-02-07 |
| Linksys (A division of Cisco Systems) | Unknown | 2007-11-30 | 2007-11-30 |
| Linux Kernel Archives | Not Vulnerable | | 2008-02-13 |
| Lucent Technologies | Unknown | 2007-11-30 | 2007-11-30 |
| Luminous Networks | Unknown | 2007-11-30 | 2007-11-30 |
| m0n0wall | Unknown | 2007-11-30 | 2007-11-30 |
| Mandriva, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| McAfee | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| Microsoft Corporation | Unknown | 2007-11-30 | 2007-11-30 |
| MontaVista Software, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Multinet (owned Process Software Corporation) | Unknown | 2007-11-30 | 2007-11-30 |
| Multitech, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| NEC Corporation | Unknown | 2007-11-30 | 2007-11-30 |
| NetBSD | Vulnerable | 2007-11-30 | 2007-12-12 |
| netfilter | Unknown | 2007-11-30 | 2007-11-30 |
| Network Appliance, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| NextHop Technologies, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Nokia | Unknown | 2008-02-05 | 2008-02-05 |
| Nortel Networks, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Novell, Inc. | Not Vulnerable | 2007-11-30 | 2008-02-01 |
| OpenBSD | Unknown | 2007-11-30 | 2007-11-30 |
| Openwall GNU/*/Linux | Unknown | 2007-11-30 | 2007-11-30 |
| PC-BSD | Unknown | 2008-02-05 | 2008-02-05 |
| QNX, Software Systems, Inc. | Vulnerable | 2007-11-30 | 2008-02-01 |
| RadWare, Inc. | Unknown | 2008-02-05 | 2008-02-05 |
| Red Hat, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Redback Networks, Inc. | Not Vulnerable | 2007-11-30 | 2008-02-05 |
| Riverstone Networks, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Secure Computing Network Security Division | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| Secureworx, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Silicon Graphics, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Slackware Linux Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| SmoothWall | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| Snort | Unknown | 2007-11-30 | 2007-11-30 |
| Sony Corporation | Unknown | 2007-11-30 | 2007-11-30 |
| Sourcefire | Unknown | 2007-11-30 | 2007-11-30 |
| Stonesoft | Unknown | 2007-11-30 | 2007-11-30 |
| Sun Microsystems, Inc. | Not Vulnerable | 2007-11-30 | 2008-02-06 |
| SUSE Linux | Unknown | 2007-11-30 | 2007-11-30 |
| Symantec, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| The SCO Group | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| TippingPoint, Technologies, Inc. | Not Vulnerable | 2007-11-30 | 2007-12-12 |
| Trustix Secure Linux | Unknown | 2007-11-30 | 2007-11-30 |
| Turbolinux | Unknown | 2007-11-30 | 2007-11-30 |
| Ubuntu | Unknown | 2007-11-30 | 2007-11-30 |
| Unisys | Unknown | 2007-11-30 | 2007-11-30 |
| Watchguard Technologies, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| Wind River Systems, Inc. | Unknown | 2007-11-30 | 2007-11-30 |
| ZyXEL | Unknown | 2007-11-30 | 2007-11-30 |
References
http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37
http://www.kame.net/
http://www.ietf.org/rfc/rfc3173.txt
http://secunia.com/advisories/28816/
http://secunia.com/advisories/28788/
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1
http://jvn.jp/cert/JVNVU%23110947/
http://www.milw0rm.com/exploits/5191
Credit
Thanks to Shoichi Sakane of the KAME project for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| Date Public | 02/06/2008 |
| Date First Published | 02/06/2008 07:05:57 AM |
| Date Last Updated | 04/29/2009 |
| CERT Advisory | |
| CVE Name | CVE-2008-0177 |
| Metric | 4.39 |
| Document Revision | 38 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |