The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://support.apple.com/kb/HT2163 | vendor advisory |
http://www.vupen.com/english/advisories/2008/1981/references | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38855 | vdb entry |
http://www.securityfocus.com/bid/26699 | vdb entry exploit |
http://www.vupen.com/english/advisories/2007/4145 | vdb entry vendor advisory |
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | vendor advisory |
http://secunia.com/advisories/27938 | third party advisory vendor advisory |
http://secunia.com/advisories/30802 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1019052 | vdb entry |
https://www.exploit-db.com/exploits/4690 | exploit |