FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-2476

This CVE name corresponds to:

Entered Topic
2009-01-05 FreeBSD -- IPv6 Neighbor Discovery Protocol routing vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-2476
Phase Assigned(20080528)

Description

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

References

Source Reference
MISC https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2008-09-036&viewMode=view
CONFIRM http://www.kb.cert.org/vuls/id/MAPG-7H2RY7
CONFIRM http://www.kb.cert.org/vuls/id/MAPG-7H2S68
CONFIRM http://support.apple.com/kb/HT3467
FREEBSD FreeBSD-SA-08:10
NETBSD NetBSD-SA2008-013
OPENBSD [4.2] 015: SECURITY FIX: October 2, 2008
OPENBSD [4.3] 006: SECURITY FIX: October 2, 2008
CERT-VN VU#472363
BID 31529
OVAL oval:org.mitre.oval:def:5670
SECUNIA 32133
VUPEN ADV-2008-2750
VUPEN ADV-2008-2751
VUPEN ADV-2008-2752
SECTRACK 1020968
SECTRACK 1021109
SECTRACK 1021132
SECUNIA 32112
SECUNIA 32117
SECUNIA 32116
SECUNIA 32406
VUPEN ADV-2009-0633
XF multiple-vendors-ndp-dos(45601)