Vulnerabilities > CVE-2007-1365 - Remote Buffer Overflow vulnerability in Openbsd 3.9/4.0

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
openbsd
critical
exploit available

Summary

Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service.

Vulnerable Configurations

Part Description Count
OS
Openbsd
2

Exploit-Db

descriptionOpenBSD 3.x/4.x ICMPV6 Packet Handling Remote Buffer Overflow Vulnerability. CVE-2007-1365. Remote exploit for openbsd platform
idEDB-ID:29725
last seen2016-02-03
modified2007-03-09
published2007-03-09
reporterAlfredo Ortega
sourcehttps://www.exploit-db.com/download/29725/
titleOpenBSD 3.x/4.x - ICMPv6 Packet Handling Remote Buffer Overflow Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/55074/CORE-2007-0219.txt
idPACKETSTORM:55074
last seen2016-12-05
published2007-03-14
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/55074/Core-Security-Technologies-Advisory-2007.0219.html
titleCore Security Technologies Advisory 2007.0219