7.2
CVSSv2

CVE-2013-3077

Published: 28/08/2013 Updated: 18/03/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 up to and including 9.2-PRERELEASE allow local users to bypass intended restrictions on kernel-memory read and write operations, and consequently gain privileges, via vectors involving a large number of source-filter entries.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.1

freebsd freebsd 9.2

freebsd freebsd 9.0

freebsd freebsd 8.3

Vendor Advisories

Debian Bug report logs - #720468 kfreebsd-9: CVE-2013-3077: local ip_multicast buffer overflow Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 11:45:02 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/ ...
Debian Bug report logs - #720475 kfreebsd-9: CVE-2013-5209: sctp kernel memory disclosure Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 12:03:06 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/90-1 ...
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a privilege escalation or information leak The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-3077 Clement Lecigne from the Google Security Team reported an integer overflow in computing the size of a temporary buf ...