CVE-2015-1417
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
25/07/2017
Last modified:
20/04/2025
Description
The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote attackers to cause a denial of service (mbuf consumption) via multiple concurrent TCP connections.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:freebsd:freebsd:8.4:-:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:beta1:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p11:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p12:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p13:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p14:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p15:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p16:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p17:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p19:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p2:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p20:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p21:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p22:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:8.4:p23:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page