Vulnerabilities > CVE-2009-0687 - Resource Management Errors vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
midnightbsd
mirbsd
netbsd
openbsd
CWE-399
exploit available

Summary

The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionMultiple Vendor PF Null Pointer Dereference Vulnerability. CVE-2009-0687. Dos exploit for bsd platform
    fileexploits/bsd/dos/8581.txt
    idEDB-ID:8581
    last seen2016-02-01
    modified2009-04-30
    platformbsd
    port
    published2009-04-30
    reporterRembrandt
    sourcehttps://www.exploit-db.com/download/8581/
    titleMultiple Vendor PF Null Pointer Dereference Vulnerability
    typedos
  • descriptionOpenBSD <= 4.5 (IP datagrams) Remote DOS Vulnerability. CVE-2009-0687. Dos exploit for openbsd platform
    fileexploits/openbsd/dos/8406.txt
    idEDB-ID:8406
    last seen2016-02-01
    modified2009-04-13
    platformopenbsd
    port
    published2009-04-13
    reporterRembrandt
    sourcehttps://www.exploit-db.com/download/8406/
    titleOpenBSD <= 4.5 IP datagrams Remote DoS Vulnerability
    typedos
  • descriptionOpenBSD <= 4.5 IP datagram Null Pointer Deref DoS Exploit. CVE-2009-0687. Dos exploit for openbsd platform
    idEDB-ID:8430
    last seen2016-02-01
    modified2009-04-14
    published2009-04-14
    reporternonroot
    sourcehttps://www.exploit-db.com/download/8430/
    titleOpenBSD <= 4.5 IP datagram Null Pointer Deref DoS Exploit