7.8
CVSSv2

CVE-2015-1414

Published: 27/02/2015 Updated: 30/05/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Integer overflow in FreeBSD prior to 8.4 p24, 9.x prior to 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote malicious users to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

Vulnerable Product Search on Vulmon Subscribe to Product

netgate pfsense 2.2.1

debian debian linux 7.0

freebsd freebsd 8.4

freebsd freebsd 9.0

freebsd freebsd 9.1

freebsd freebsd 9.2

freebsd freebsd 10.1

freebsd freebsd 9.3

freebsd freebsd 10.0

Vendor Advisories

Debian Bug report logs - #779194 kfreebsd-10: CVE-2014-0998: vt crash via ioctl Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 25 Feb 2015 11:39:01 UTC Severity: grave Tags: patch, secu ...
Debian Bug report logs - #782107 kfreebsd-10: CVE-2015-2923: IPv6 Hop limit lowering via RA messages Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 7 Apr 2015 21:45:07 UTC Severity: gr ...
Debian Bug report logs - #779195 kfreebsd-10: CVE-2015-1414: DoS via IGMP packet Package: src:kfreebsd-10; Maintainer for src:kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Wed, 25 Feb 2015 11:39:08 UTC Severity: grave Tags: patch, sec ...
Mateusz Kocielski and Marek Kroemeke discovered that an integer overflow in IGMP processing may result in denial of service through malformed IGMP packets For the stable distribution (wheezy), this problem has been fixed in version 90-10+deb709 We recommend that you upgrade your kfreebsd-9 packages ...