Description
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.
References (6)
Core 6
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3175
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72777
Vendor Advisory vendor-advisory
x_refsource_freebsd
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc
Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10107
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031798
Third Party Advisory x_refsource_confirm
https://www.pfsense.org/security/advisories/pfSense-SA-15_02.igmp.asc
Scores
EPSS
0.0056
EPSS Percentile
68.6%
Details
Status
published
Products (9)
debian/debian_linux
7.0
freebsd/freebsd
8.4
freebsd/freebsd
9.0
freebsd/freebsd
9.1
freebsd/freebsd
9.2
freebsd/freebsd
9.3
freebsd/freebsd
10.0
freebsd/freebsd
10.1
netgate/pfsense
2.2.1
Published
Feb 27, 2015
Tracked Since
Feb 18, 2026