The pf_test_rule function in OpenBSD Packet Filter (PF), as used...
Vulnerability Description
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0687
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/53608
- http://www.openbsd.org/errata43.html#013_pf
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-001.txt.asc
- https://www.exploit-db.com/exploits/8406
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49837
- http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt
- http://www.securityfocus.com/archive/1/502634
- https://www.exploit-db.com/exploits/8581
- http://www.openbsd.org/errata44.html#013_pf
- http://www.vupen.com/english/advisories/2009/1015
- ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/013_pf.patch
- http://www.openbsd.org/errata45.html#002_pf
Affected Vendor
midnightbsd
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.