CVE-2015-1414

FreeBSD <8.4-10.1 - DoS

Title source: llm
STIX 2.1

Description

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3175
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72777
Vendor Advisory vendor-advisory x_refsource_freebsd
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031798

Scores

EPSS 0.0056
EPSS Percentile 68.6%

Details

Status published
Products (9)
debian/debian_linux 7.0
freebsd/freebsd 8.4
freebsd/freebsd 9.0
freebsd/freebsd 9.1
freebsd/freebsd 9.2
freebsd/freebsd 9.3
freebsd/freebsd 10.0
freebsd/freebsd 10.1
netgate/pfsense 2.2.1
Published Feb 27, 2015
Tracked Since Feb 18, 2026