PT-2018-4402 · Freebsd · Freebsd

Hiroki Sato

·

Published

2018-02-05

·

Updated

2018-03-14

·

CVE-2015-5674

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions FreeBSD versions 9.3 before 9.3-RELEASE-p22 FreeBSD versions 10.2-RC2 before 10.2-RC2-p1 FreeBSD versions 10.2-RC1 before 10.2-RC1-p2 FreeBSD versions 10.2 before 10.2-BETA2-p3 FreeBSD versions 10.1 before 10.1-RELEASE-p17
Description The issue allows remote authenticated users to cause a denial of service via a query from a network that is not directly connected, resulting in an assertion failure and daemon exit.
Recommendations For FreeBSD version 9.3, update to 9.3-RELEASE-p22 or later. For FreeBSD version 10.2-RC2, update to 10.2-RC2-p1 or later. For FreeBSD version 10.2-RC1, update to 10.2-RC1-p2 or later. For FreeBSD version 10.2, update to 10.2-BETA2-p3 or later. For FreeBSD version 10.1, update to 10.1-RELEASE-p17 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5674

Affected Products

Freebsd