CVE-2015-1414

high
Published 2015-02-27 · Modified 2026-05-06
CVSS v3
VIR risk
7.8

Description

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debian7.0affected
freebsd freebsd8.4affected
freebsd freebsd9.0affected
freebsd freebsd9.1affected
freebsd freebsd9.2affected
freebsd freebsd9.3affected
freebsd freebsd10.0affected
freebsd freebsd10.1affected

Application impact

VendorProductVersionsFixed
netgatepfsense2.2.1

References

💬 Discuss CVE-2015-1414 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.