← Vulnerability feed

Vulnerability record · CVE-2008-0177 · published 7 February 2008

CVE-2008-0177: Kame ipcomp vulnerability

Kame · Ipcomp

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

7.8 CVSS 2.0 High EPSS 16% · top 3.3%
7.8CVSS 2.0 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References
16 Jun 2026Last modified by NVD

Description

The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1 Vendor Advisory
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://secunia.com/advisories/28788 PatchVendor Advisory
http://secunia.com/advisories/28816 Vendor Advisory
http://secunia.com/advisories/28979
http://secunia.com/advisories/29130
http://secunia.com/advisories/30430
http://secunia.com/advisories/31074
http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc
http://securitytracker.com/id?1019314
http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36%3Br2=1.37
http://www.kb.cert.org/vuls/id/110947 US Government Resource
http://www.securityfocus.com/bid/27642 Patch
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/0441
http://www.vupen.com/english/advisories/2008/0688
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/2094/references
https://www.exploit-db.com/exploits/5191
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&only_with_tag=netbsd-3-1 Vendor Advisory
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
http://secunia.com/advisories/28788 PatchVendor Advisory
http://secunia.com/advisories/28816 Vendor Advisory
http://secunia.com/advisories/28979
http://secunia.com/advisories/29130
http://secunia.com/advisories/30430
http://secunia.com/advisories/31074
http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc
http://securitytracker.com/id?1019314
http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36%3Br2=1.37
http://www.kb.cert.org/vuls/id/110947 US Government Resource
http://www.securityfocus.com/bid/27642 Patch
http://www.us-cert.gov/cas/techalerts/TA08-150A.html US Government Resource
http://www.vupen.com/english/advisories/2008/0441
http://www.vupen.com/english/advisories/2008/0688
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/2094/references
https://www.exploit-db.com/exploits/5191

Track CVE-2008-0177 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2008-0177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.