SB2014050204 - Buffer overflow in FreeBSD



SB2014050204 - Buffer overflow in FreeBSD

Published: May 2, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014050204
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2014-3000)

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly read system memory via multiple crafted packets, related to moving a reassemble queue entry to the segment list when the queue is full.


Remediation

Install update from vendor's website.