CVE-2015-1414

high

Description

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

References

https://www.pfsense.org/security/advisories/pfSense-SA-15_02.igmp.asc

https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc

https://kc.mcafee.com/corporate/index?page=content&id=SB10107

http://www.securitytracker.com/id/1031798

http://www.securityfocus.com/bid/72777

http://www.debian.org/security/2015/dsa-3175

Details

Source: Mitre, NVD

Published: 2015-02-27

Updated: 2019-05-30

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High