Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <EB827399-3A32-4192-A514-0EB847E2253E@omniti.com>
Date: Thu, 2 Apr 2015 19:55:19 -0400
From: Dan McDonald <danmcd@...iti.com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: CVE Request : IPv6 Hop limit lowering via RA messages

> On Apr 2, 2015, at 1:19 PM, D.S. Ljungmark <ljungmark@...io.se> wrote:
> 
> An unprivileged user on a local network can use IPv6 Neighbour
> Discovery ICMP to broadcast a non-route with a low hop limit, this
> causing machines to lower the hop limit on existing IPv6 routes.
> 

This low-hop-limit problem does not affect Illumos, but we added detection of the problem into our IPv6 NDP daemon:  

	https://marc.info/?l=illumos-developer&m=142748230615203&w=2

I can't speak to our cousins in Oracle Solaris, though.

FYI,
Dan McDonald - OmniOS Engineering

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.