KAME contains a flaw related to the rtadvd daemon that may allow an attacker to cause a denial of service condition. By default, the rtadvd daemon accepted router renumbering input, which could lead to an attacker manipulating the router's configuration, rerouting traffic, or causing a denial of service condition. No further details have been provided.
Classification
Location:
Location Unknown
Attack Type:
Denial of Service,
Input Manipulation,
Misconfiguration
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version 1.508 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by applying the vendor-supplied patch.
We currently have no CVSS2 data on this vulnerability. Feel free to suggest it.
Blogs
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.