5
CVSSv2

CVE-2014-7250

Published: 12/12/2014 Updated: 12/12/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote malicious users to cause a denial of service (resource consumption) via crafted packets.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openbsd 3.6

netbsd netbsd 2.0

freebsd freebsd 5.4

bsd bsd 4.3

Vendor Advisories

Debian Bug report logs - #778367 kfreebsd-10: CVE-2014-7250 resource consumption issue Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sat, 14 Feb 2015 04:12:02 UTC Severity: important Tags: mo ...