Summary
The remote host is missing an update to the system as announced in the referenced advisory FreeBSD-SA-07:03.ipv6.asc
Solution
Upgrade your system to the appropriate stable release or security branch dated after the correction date
https://secure1.securityspace.com/smysecure/catid.html?in=FreeBSD-SA-07:03.ipv6.asc
Insight
IPv6 provides a routing header option which allows a packet sender to indicate how the packet should be routed, overriding the routing knowledge present in a network. This functionality is roughly equivalent to the source routing option in IPv4. All nodes in an IPv6 network -- both routers and hosts -- are required by RFC 2640 to process such headers.
There is no mechanism for preventing IPv6 routing headers from being used to route packets over the same link(s) many times.
Severity
Classification
-
CVE CVE-2007-2242 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities