Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g6hh-x63c-83gf

Опубликовано: 06 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.

As a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.

In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.

As a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.

EPSS

Процентиль: 64%
0.00475
Низкий

7.5 High

CVSS3

Дефекты

CWE-167

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is. As a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость компонента фильтрации пакетов pf (packet filter) операционной системы FreeBSD, позволяющая нарушителю обойти существующие правила брандмауэра

EPSS

Процентиль: 64%
0.00475
Низкий

7.5 High

CVSS3

Дефекты

CWE-167