sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 00:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc - | |
| References | () http://lists.apple.com/archives/security-announce/2009/May/msg00002.html - | |
| References | () http://secunia.com/advisories/31745 - Vendor Advisory | |
| References | () http://secunia.com/advisories/32401 - | |
| References | () http://secunia.com/advisories/35074 - | |
| References | () http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc - Patch | |
| References | () http://support.apple.com/kb/HT3467 - | |
| References | () http://support.apple.com/kb/HT3549 - | |
| References | () http://www.securityfocus.com/bid/31004 - Patch | |
| References | () http://www.securitytracker.com/id?1020820 - | |
| References | () http://www.securitytracker.com/id?1021111 - | |
| References | () http://www.us-cert.gov/cas/techalerts/TA09-133A.html - US Government Resource | |
| References | () http://www.vupen.com/english/advisories/2009/0633 - | |
| References | () http://www.vupen.com/english/advisories/2009/1297 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44908 - | 
Information
                Published : 2008-09-05 16:08
Updated : 2025-04-09 00:30
NVD link : CVE-2008-3530
Mitre link : CVE-2008-3530
CVE.ORG link : CVE-2008-3530
JSON object : View
Products Affected
                freebsd
- freebsd
 
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
