CVE-2007-1338 Information

Description

The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the \Block incoming IPv6 connections\ setting which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4.

Reference

http://arstechnica.com/journals/apple.ars/2007/2/14/7063 http://docs.info.apple.com/article.html?artnum=305366 http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html http://osvdb.org/34843 http://secunia.com/advisories/24830 http://www.securitytracker.com/id?1017889 http://www.vupen.com/english/advisories/2007/1308 https://exchange.xforce.ibmcloud.com/vulnerabilities/33526

Share on: