CVE-2014-7250 Information

Description

The TCP stack in 4.3BSD Net/2 as used in FreeBSD 5.4 NetBSD possibly 2.0 and OpenBSD possibly 3.6 does not properly implement the session timer which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.

Reference

http://jvn.jp/en/jp/JVN07930208/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000134 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=195243

Share on: