I-D Action: draft-gont-6man-ipv6-atomic-fragments-00.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.

	Title           : Processing of IPv6 "atomic" fragments
	Author(s)       : Fernando Gont
	Filename        : draft-gont-6man-ipv6-atomic-fragments-00.txt
	Pages           : 12
	Date            : 2011-12-15

   IPv6 allows packets to contain a Fragment Header, without the packet
   being actually fragmented into multiple pieces.  Such packets
   typically result from hosts that have received an ICMPv6 "Packet Too
   Big" error message that advertises a "Next-Hop MTU" smaller than 1280
   bytes, and are currently processed by hosts as "fragmented traffic".
   By forging ICMPv6 "Packet Too Big" error messages an attacker can
   cause hosts to employ "atomic fragments", and the launch any
   fragmentation-based attacks against such traffic.  This document
   discusses the generation of the aforementioned "atomic fragments",
   the corresponding security implications, and formally updates RFC
   2460 and RFC 5722 such that the attack vector based on "atomic
   fragments" is completely eliminated.


A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-gont-6man-ipv6-atomic-fragments-00.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-gont-6man-ipv6-atomic-fragments-00.txt

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux