CVE-2014-3711CVE-2014-3711

Affected configuration(s):

cpe:/o:freebsd:freebsd:9.1
cpe:/o:freebsd:freebsd:9.1:release-p4
cpe:/o:freebsd:freebsd:9.1:release-p5
cpe:/o:freebsd:freebsd:9.2:-
cpe:/o:freebsd:freebsd:9.2:prerelease
cpe:/o:freebsd:freebsd:9.2:rc1
cpe:/o:freebsd:freebsd:9.2:rc2
cpe:/o:freebsd:freebsd:9.3
cpe:/o:freebsd:freebsd:9.3:rc1
cpe:/o:freebsd:freebsd:9.3:rc2
cpe:/o:freebsd:freebsd:10.0
cpe:/o:freebsd:freebsd:10.0:rc1
cpe:/o:freebsd:freebsd:10.0:rc2
cpe:/o:freebsd:freebsd:10.1
cpe:/o:freebsd:freebsd:10.1:rc1
cpe:/o:freebsd:freebsd:10.1:rc2

Date published: 2014-10-27T11:55:24.110-04:00

Date last modified: 2014-11-18T22:01:34.893-05:00

CVSS Score: 5.0

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: http://www.debian.org/security/2014/dsa-3070

Summary: namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.