KAME Project "ipcomp6_input()" Denial of Service - Advisories - Secunia

KAMEプロジェクトのipcomp6_input()関数にDoSを受ける脆弱性が存在するそうです。

特殊に細工された(IPCompを含んだ)IPv6パケットを送ることでクラッシュさせることが出来るそうです。

A vulnerability has been reported in the KAME Project, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error within the "ipcomp6_input()" function in kame/sys/netinet6/ipcomp_input.c when processing IPv6 packets with an IPComp header. This can be exploited to crash a vulnerable system by sending a specially crafted IPv6 packet.

screenshot