Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kenji Rikitake

Researcher fromJapan IPA
#49477of 53,633
5Total CVSS
Vulnerabilities · 1
PT-2014-7856
5.0
2014-12-12
Openbsd · Openbsd · CVE-2014-7250
**Name of the Vulnerable Software and Affected Versions** FreeBSD version 5.4 NetBSD versions possibly 2.0 OpenBSD versions possibly 3.6 **Description** The issue is related to the TCP stack implementation, specifically the session timer, which can be exploited by remote attackers to cause a denial of service through resource consumption by sending crafted packets. **Recommendations** For FreeBSD version 5.4, update the TCP stack implementation to properly handle session timers. For NetBSD versions possibly 2.0, consider disabling the vulnerable TCP stack functionality until a proper fix is available. For OpenBSD versions possibly 3.6, restrict access to the TCP stack to minimize the risk of exploitation.