>> FreeBSD ICMPv6 "Packet Too Big" Message DoS Vulnerability
Title : FreeBSD ICMPv6 "Packet Too Big" Message DoS Vulnerability VUPEN ID : VUPEN/ADV-2008-2500 CVE ID : CVE-2008-3530 CWE ID : CWE-19
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-05
Technical Description
A vulnerability has been identified in FreeBSD, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an error in the "icmp6_mtudisc_update()" [sys/netinet6/icmp6.c] function when processing specially crafted ICMPv6 "Packet Too Big" messages, which could allow remote attackers to cause the TCP stack of the kernel to panic, creating a denial of service condition.