4
CVSSv2

CVE-2014-1453

Published: 16/04/2014 Updated: 18/03/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The NFS server (nfsserver) in FreeBSD 8.3 up to and including 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involving a thread that uses the correct locking order.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.0

freebsd freebsd 9.1

freebsd freebsd 8.4

freebsd freebsd 9.2

freebsd freebsd 10.0

freebsd freebsd 8.3

Vendor Advisories

Debian Bug report logs - #743984 kfreebsd-9: CVE-2014-1453: nfsserver denial of service Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 9 Apr 2014 00:00:02 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/90-10, ...
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or possibly disclosure of kernel memory The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-1453 A remote, authenticated attacker could cause the NFS server become deadlocked, resulting in a deni ...