7.8
CVSSv2

CVE-2014-3000

Published: 02/05/2014 Updated: 21/06/2014
CVSS v2 Base Score: 7.8 | Impact Score: 7.8 | Exploitability Score: 8.6
VMScore: 694
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:C

Vulnerability Summary

The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote malicious users to cause a denial of service (undefined memory access and system crash) or possibly read system memory via multiple crafted packets, related to moving a reassemble queue entry to the segment list when the queue is full.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.1

freebsd freebsd 8.3

freebsd freebsd 9.2

freebsd freebsd 10.0

freebsd freebsd 8.4

Vendor Advisories

Debian Bug report logs - #743984 kfreebsd-9: CVE-2014-1453: nfsserver denial of service Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 9 Apr 2014 00:00:02 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/90-10, ...
Debian Bug report logs - #746949 CVE-2014-3000: TCP reassembly vulnerability Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Robert Millan <rmh@debianorg> Date: Sun, 4 May 2014 09:48:02 UTC Severity: grave Tags: fixed-upstream, security Found ...
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or possibly disclosure of kernel memory The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-1453 A remote, authenticated attacker could cause the NFS server become deadlocked, resulting in a deni ...