Vulnerability Description
Miredo 0.9.8 through 1.0.5 does not properly authenticate a Teredo bubble during UDP hole punching with HMAC-MD5-64 hashing, which allows remote attackers to impersonate an arbitrary Teredo client.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miredo | Miredo | <= 1.0.5 |
References
- http://secunia.com/advisories/23596PatchVendor Advisory
- http://www.simphalempin.com/dev/miredo/mtfl-sa-0604.shtml.en
- http://www.vupen.com/english/advisories/2007/0029
- http://secunia.com/advisories/23596PatchVendor Advisory
- http://www.simphalempin.com/dev/miredo/mtfl-sa-0604.shtml.en
- http://www.vupen.com/english/advisories/2007/0029
FAQ
What is CVE-2006-6858?
CVE-2006-6858 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Miredo 0.9.8 through 1.0.5 does not properly authenticate a Teredo bubble during UDP hole punching with HMAC-MD5-64 hashing, which allows remote attackers to impersonate an arbitrary Teredo client.
How severe is CVE-2006-6858?
CVE-2006-6858 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6858?
Check the references section above for vendor advisories and patch information. Affected products include: Miredo Miredo.