CVE-2015-1414

NameCVE-2015-1414
DescriptionInteger overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3175-1, DSA-3175-2
NVD severityhigh (attack range: remote)
Debian Bugs779195, 779201, 779202

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kfreebsd-10 (PTS)jessie10.1~svn274115-4fixed
stretch, sid10.3~svn300087-3fixed
kfreebsd-8 (PTS)wheezy8.3-6+deb7u1vulnerable
kfreebsd-9 (PTS)wheezy, wheezy (security)9.0-10+deb70.10fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kfreebsd-10source(unstable)10.1~svn274115-4high779195
kfreebsd-11unknownexperimental11.0~svn284956-1high
kfreebsd-8source(unstable)(unfixed)high779202
kfreebsd-8sourcesqueeze(not affected)
kfreebsd-9source(unstable)(unfixed)high779201
kfreebsd-9sourcewheezy9.0-10+deb70.10highDSA-3175-2

Notes

[wheezy] - kfreebsd-8 <no-dsa> (kfreebsd-8 only a test kernel, will be fixed in a point update)
[squeeze] - kfreebsd-8 <not-affected> (kfreebsd-i386/amd64 not supported in Squeeze LTS)
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc

Search for package or bug name: Reporting problems