Miredo 0.9.8 through 1.0.5 does not properly authenticate a Teredo bubble during UDP hole punching with HMAC-MD5-64 hashing, which allows remote attackers to impersonate an arbitrary Teredo client.
References
| Link | Resource |
|---|---|
| http://www.simphalempin.com/dev/miredo/mtfl-sa-0604.shtml.en | |
| http://secunia.com/advisories/23596 | Patch Vendor Advisory |
| http://www.vupen.com/english/advisories/2007/0029 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-12-30 21:00
Updated : 2011-03-07 18:47
NVD link : CVE-2006-6858
Mitre link : CVE-2006-6858
JSON object : View
CWE
Products Affected
miredo
- miredo


