CVE-2017-1081
10.04.2018, 13:29
In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially crafted packet fragments due to incorrect memory handling.Enginsight
Vendor | Product | Version |
---|---|---|
freebsd | freebsd | 𝑥 ≤ 11.0 |
freebsd | freebsd | 10.3 |
freebsd | freebsd | 10.3:p19 |
freebsd | freebsd | 11.0:p10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-416 - Use After FreeReferencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References