OpenBSD flaw exploits IPv6 weakness

Researchers released an advisory today disclosing a remote kernel buffer overflow flaw in the OpenBSD operating system that they claim is the first exploitable IPv6 vulnerability to be publicly disclosed with a proof-of-concept exploit.

Discovered by experts with Core Security, the vulnerability allows attackers to gain complete control of an OpenBSD machine by sending malformed IPv6 packets.

“In order to perform such an attack, the attacker must be either on the same network as the target system or on a network that can route packets to the target system,” said Ivan Arce, CTO of Core Security.

Arce said that Core Security worked with OpenBSD developers to close the security hole in the system before disclosing the flaw. Users are highly encouraged to download the patch and recompile the kernel to secure their systems from an attack.

He said that the vulnerability highlights the fact that no operating system is impervious to security bugs, even one as hardened as OpenBSD. He also explained that this flaw should act as a warning to those deploying the IPv6 protocol.

"It’s an IPv6 problem and we wanted to point that out because it is an example of how implementing a complex protocol, even in one of the most robust and secure operating systems such as OpenBSD, could be prone to errors and implementation bugs,” he said.

“Since IPv6 is starting to pick up in terms of adoption, we felt that it was important to talk about this.”
OpenBSD flaw exploits IPv6 weakness

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read