CVE-2015-1414

NameCVE-2015-1414
DescriptionInteger overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3175-1, DSA-3175-2
Debian Bugs779195, 779201, 779202

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kfreebsd-10 (PTS)jessie10.1~svn274115-4fixed
stretch10.3~svn300087-3fixed
buster10.3~svn300087-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kfreebsd-10source(unstable)10.1~svn274115-4779195
kfreebsd-11unknownexperimental11.0~svn284956-1
kfreebsd-8sourcesqueeze(not affected)
kfreebsd-8source(unstable)(unfixed)779202
kfreebsd-9sourcewheezy9.0-10+deb70.10DSA-3175-2
kfreebsd-9source(unstable)(unfixed)779201

Notes

[wheezy] - kfreebsd-8 <no-dsa> (kfreebsd-8 only a test kernel, will be fixed in a point update)
[squeeze] - kfreebsd-8 <not-affected> (kfreebsd-i386/amd64 not supported in Squeeze LTS)
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc

Search for package or bug name: Reporting problems