CVE-2007-1365
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 18%
from disclosure to weapon0 days
Published on NVDMar 10
1st PoCMar 9
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/29725⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=openbsd-cvs&m=117252151023868&w=2http://secunia.com/advisories/24490http://securitytracker.com/id?1017735http://www.coresecurity.com/?action=item&id=1703http://www.kb.cert.org/vuls/id/986425http://www.openbsd.org/errata39.html#m_dup1http://www.openbsd.org/errata40.html#m_dup1http://www.osvdb.org/33050http://www.securityfocus.com/bid/22901http://www.securitytracker.com/id?1017744