PT-2016-4910 · Freebsd · Freebsd
Jonathan T. Looney
+1
·
Published
2016-01-14
·
Updated
2016-03-02
·
CVE-2016-1882
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 9.3 before p33
FreeBSD versions 10.1 before p26
FreeBSD versions 10.2 before p9
Description
The issue allows remote attackers to cause a denial of service, resulting in a kernel crash. This is achieved through vectors related to creating a TCP connection with the
TCP MD5SIG and TCP NOOPT socket options.Recommendations
For FreeBSD version 9.3, update to p33 or later.
For FreeBSD version 10.1, update to p26 or later.
For FreeBSD version 10.2, update to p9 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd