Remote Denial of Service in OpenBSD Packet Filter Affecting OpenBSD, NetBSD, and MirOS
CVE-2009-0687

Currently unrated

Key Information:

Vendor
OpenBSD
Vendor
CVE Published:
11 August 2009

Summary

The vulnerability exists in the pf_test_rule function found within the OpenBSD Packet Filter (PF) used across various operating systems. It enables remote attackers to induce a denial of service condition by sending specifically crafted IPv4 packets containing an ICMPv6 payload, which can lead to a NULL pointer dereference and ultimately, system panic. This affects OpenBSD versions 4.2 through 4.5, specific versions of NetBSD, and other related systems.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.