Advisory Details

November 10th, 2010

Apple Mac OS X IPv6 PIM Denial of Service Vulnerability

ZDI-10-248
ZDI-CAN-857

CVE ID CVE-2010-1843
CVSS SCORE 7.8, AV:N/AC:L/Au:N/C:N/I:N/A:C
AFFECTED VENDORS Apple
AFFECTED PRODUCTS OS X
TREND MICRO CUSTOMER PROTECTION Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID ['10608']. For further product information on the TippingPoint IPS: http://www.tippingpoint.com
VULNERABILITY DETAILS

This vulnerability allows remote attackers to denial of service the IPv6 stack of an installation of Apple Mac OSX. No authentication or user interaction is required in order to exploit this vulnerability.

The specific flaw exists within OSX's IPv6 stack. A NULL pointer dereference vulnerability was discovered in the xnu kernel implementation when a specially formatted packet is sent to it. Exploiting this vulnerability will result in a remote denial of service against the target os.

ADDITIONAL DETAILS

Mac OS X 10.6.5: http://support.apple.com/kb/HT4435

iOS 4.2: http://support.apple.com/kb/HT4456


DISCLOSURE TIMELINE
  • 2010-08-17 - Vulnerability reported to vendor
  • 2010-11-10 - Coordinated public release of advisory
CREDIT Anonymous
BACK TO ADVISORIES