CVE Vulnerabilities

CVE-2014-7250

Published: Dec 12, 2014 | Modified: Dec 12, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.

Affected Software

Name Vendor Start Version End Version
Bsd Bsd 4.3 (including) 4.3 (including)
Freebsd Freebsd 5.4 (including) 5.4 (including)
Netbsd Netbsd 2.0 (including) 2.0 (including)
Openbsd Openbsd 3.6 (including) 3.6 (including)

References