PT-2018-4402 · Freebsd · Freebsd
Hiroki Sato
·
Published
2018-02-05
·
Updated
2018-03-14
·
CVE-2015-5674
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 9.3 before 9.3-RELEASE-p22
FreeBSD versions 10.2-RC2 before 10.2-RC2-p1
FreeBSD versions 10.2-RC1 before 10.2-RC1-p2
FreeBSD versions 10.2 before 10.2-BETA2-p3
FreeBSD versions 10.1 before 10.1-RELEASE-p17
Description
The issue allows remote authenticated users to cause a denial of service via a query from a network that is not directly connected, resulting in an assertion failure and daemon exit.
Recommendations
For FreeBSD version 9.3, update to 9.3-RELEASE-p22 or later.
For FreeBSD version 10.2-RC2, update to 10.2-RC2-p1 or later.
For FreeBSD version 10.2-RC1, update to 10.2-RC1-p2 or later.
For FreeBSD version 10.2, update to 10.2-BETA2-p3 or later.
For FreeBSD version 10.1, update to 10.1-RELEASE-p17 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd