SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#267289

IPv6 Type 0 Route Headers allow sender to control routing

Overview

IPv6 Type 0 Route Headers allow the sender to control packet routing. This vulnerability may allow an attacker to cause a denial-of-service condition.

I. Description

Routing header options provided by IPv6 allow packet senders to indicate specific nodes through which the packet should travel. Note that a node is defined as any device that implements IPv6, which includes hosts as well as routing devices. According to FreeBSD-SA-07:03.ipv6:

    An attacker can "amplify" a denial of service attack against a link between two vulnerable hosts; that is, by sending a small volume of traffic the attacker can consume a much larger amount of bandwidth between the two vulnerable hosts.

    An attacker can use vulnerable hosts to "concentrate" a denial of service attack against a victim host or network; that is, a set of packets sent over a period of 30 seconds or more could be constructed such that they all arrive at the victim within a period of 1 second or less.

II. Impact

This condition can facilitate a number of different impacts including packet amplification, bypassing filtering devices, denial of service, and defeating IPv6 Anycast.

III. Solution

Update

See the systems affected portion of this document for information about updates for specific vendors.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown9-May-2007
AlcatelUnknown9-May-2007
Apple Computer, Inc.Vulnerable21-Jun-2007
AT&TUnknown9-May-2007
Avaya, Inc.Unknown9-May-2007
Avici Systems, Inc.Unknown9-May-2007
Borderware TechnologiesUnknown9-May-2007
Charlotte's Web NetworksUnknown9-May-2007
Check Point Software TechnologiesUnknown9-May-2007
Chiaro Networks, Inc.Unknown9-May-2007
Cisco Systems, Inc.Vulnerable15-May-2007
ClavisterUnknown9-May-2007
Computer AssociatesUnknown9-May-2007
Cray Inc.Unknown9-May-2007
D-Link Systems, Inc.Unknown9-May-2007
Data Connection, Ltd.Unknown9-May-2007
EMC, Inc. (formerly Data General Corporation)Unknown9-May-2007
EricssonUnknown9-May-2007
eSoft, Inc.Unknown9-May-2007
Extreme NetworksUnknown9-May-2007
F5 Networks, Inc.Unknown9-May-2007
Force10 Networks, Inc.Unknown9-May-2007
Fortinet, Inc.Unknown9-May-2007
Foundry Networks, Inc.Unknown9-May-2007
FreeBSD, Inc.Vulnerable14-May-2007
FujitsuVulnerable15-Jun-2007
Global Technology AssociatesUnknown9-May-2007
Hewlett-Packard CompanyUnknown9-May-2007
HitachiVulnerable14-May-2007
HyperchipUnknown9-May-2007
IBM CorporationUnknown9-May-2007
IBM Corporation (zseries)Unknown9-May-2007
IBM eServerUnknown9-May-2007
Ingrian Networks, Inc.Unknown9-May-2007
Intel CorporationUnknown9-May-2007
Internet Initiative JapanVulnerable14-May-2007
Internet Security Systems, Inc.Unknown9-May-2007
IntotoUnknown9-May-2007
IP FilterUnknown9-May-2007
Juniper Networks, Inc.Unknown9-May-2007
Linksys (A division of Cisco Systems)Unknown9-May-2007
Lucent TechnologiesUnknown9-May-2007
Luminous NetworksUnknown9-May-2007
Microsoft CorporationUnknown9-May-2007
MontaVista Software, Inc.Unknown9-May-2007
Multinet (owned Process Software Corporation)Unknown9-May-2007
Multitech, Inc.Unknown9-May-2007
NEC CorporationVulnerable15-Jun-2007
NetBSDUnknown9-May-2007
netfilterUnknown9-May-2007
Network Appliance, Inc.Unknown9-May-2007
NextHop Technologies, Inc.Unknown9-May-2007
NokiaUnknown9-May-2007
Nortel Networks, Inc.Unknown9-May-2007
Novell, Inc.Not Vulnerable17-May-2007
OpenBSDVulnerable14-May-2007
QNX, Software Systems, Inc.Unknown9-May-2007
Red Hat, Inc.Vulnerable17-May-2007
Redback Networks, Inc.Unknown9-May-2007
Riverstone Networks, Inc.Unknown9-May-2007
rPathVulnerable21-Jun-2007
Secure Computing Network Security DivisionVulnerable15-Jun-2007
Secureworx, Inc.Unknown9-May-2007
Silicon Graphics, Inc.Unknown9-May-2007
Sony CorporationUnknown9-May-2007
StonesoftUnknown9-May-2007
Sun Microsystems, Inc.Vulnerable17-May-2007
Symantec, Inc.Unknown9-May-2007
The SCO GroupUnknown9-May-2007
UnisysUnknown9-May-2007
Watchguard Technologies, Inc.Unknown9-May-2007
Wind River Systems, Inc.Unknown9-May-2007
ZyXELUnknown9-May-2007

References


http://secunia.com/advisories/24978/
http://openbsd.org/errata40.html#012_route6
http://secunia.com/advisories/25033/
http://www.secdev.org/conf/IPv6_RH_security-csw07.pdf
http://secunia.com/advisories/25068/
http://www.ietf.org/rfc/rfc2460.txt
http://docs.info.apple.com/article.html?artnum=305712
http://secunia.com/advisories/25770/

Credit

This vulnerability was reported by Philippe Biondi Arnaud Ebalard of EADS Innovation Works — IW/SE/CS, IT Sec lab, Suresnes, France at CanSecWest 2007.

This document was written by Chris Taschner.

Other Information

Date Public:2007-04-24
Date First Published:2007-06-13
Date Last Updated:2007-06-26
CERT Advisory: 
CVE-ID(s):CVE-2007-2242
NVD-ID(s):CVE-2007-2242
US-CERT Technical Alerts: 
Metric:11.03
Document Revision:33

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader