PT-2017-6487 · Freebsd · Freebsd

Patrick Kelsey

·

Published

2017-07-25

·

Updated

2019-03-20

·

CVE-2015-1417

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD versions prior to 10.2-PRERELEASE FreeBSD versions prior to 10.1-RELEASE-p16 FreeBSD versions prior to 9.3-STABLE FreeBSD versions prior to 9.3-RELEASE-p21 FreeBSD versions prior to 8.4-STABLE FreeBSD versions prior to 8.4-RELEASE-p35
Description The issue allows remote attackers to cause a denial of service by consuming mbuf via multiple concurrent TCP connections on systems with VNET enabled and at least 16 VNET instances.
Recommendations For versions prior to 10.2-PRERELEASE, update to 10.2-PRERELEASE or later. For versions prior to 10.1-RELEASE-p16, update to 10.1-RELEASE-p16 or later. For versions prior to 9.3-STABLE, update to 9.3-STABLE or later. For versions prior to 9.3-RELEASE-p21, update to 9.3-RELEASE-p21 or later. For versions prior to 8.4-STABLE, update to 8.4-STABLE or later. For versions prior to 8.4-RELEASE-p35, update to 8.4-RELEASE-p35 or later.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1417

Affected Products

Freebsd