vendor:
Kaspersky Internet Security 2013
by:
Marc Heuse
7,8
CVSS
HIGH
Remote System Freeze
N/A
CWE
Product Name: Kaspersky Internet Security 2013
Affected Version From: Kaspersky Internet Security 2013
Affected Version To: Kaspersky Internet Security 2013
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
Kaspersky Internet Security 2013 Remote System Freeze
Kaspersky Internet Security 2013 (and any other Kaspersky product which includes the firewall funcionality) is susceptible to a remote system freeze. If IPv6 connectivity to a victim is possible (which is always the case on local networks), a fragmented packet with multiple but one large extension header leads to a complete freeze of the operating system. No log message or warning window is generated, nor is the system able to perform any task.
Mitigation:
Remove the Kaspersky Anti-Virus NDIS 6 Filter from all network interfaces or uninstall the Kaspersky software until a fix is provided.