>> OpenBSD Security Update Fixes Remote Denial of Service Vulnerabilities
Title : OpenBSD Security Update Fixes Remote Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0660 CVE ID : CVE-2008-1057 - CVE-2008-1058
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-25
Technical Description
Two vulnerabilities have been identified in OpenBSD, which could be exploited by remote attackers to cause a denial of service. These issues are caused by errors in the "tcp_respond()" [sys/netinet/tcp_subr.c] and "ip6_check_rh0hdr()" [sys/netinet6/ip6_input.c] functions when processing malformed packets, which could be exploited by remote attackers to panic a vulnerable system, creating a denial of service condition.