CVE-2018-6923
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/09/2018
Last modified:
13/11/2018
Description
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the machine to consume excessive resources.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:4.11:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



