Description: A vulnerability has been reported in OpenBSD, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a memory corruption within the "mbuf" handling of ICMP6 packets. This can be exploited to cause a kernel panic or execute arbitrary code with kernel privileges.
Successful exploitation requires that an attacker can send fragmented ICMPv6 packets to a target local system.
The vulnerability is reported in versions 3.1 through 4.0. Other versions may also be affected.
Solution: Apply patches or filter IPv6 packets as a workaround.
Changelog: 2007-03-14: Updated advisory with new information from Core Security. Increased criticality.
2007-03-14: Added CVE reference.
2007-03-16: Added link to US-CERT.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.