CVE-2009-0687
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
- Affected products
- Midnightbsd, Miros, Netbsd, Openbsd
- Midnightbsd
- = 0.3-current
- Mirbsd Miros
- ≤ 10
- Netbsd
- = 5.0
- Openbsd
- = 4.2, 4.3, 4.4, 4.5
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 9.5% (95th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2009-08-11
CVE-2009-0687 at NVD
3 known exploits for CVE-2009-0687
Proof-of-concept code and exploit modules indexed by Sploitus