CVE-2002-0574

Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being removed.
References
Link Resource
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:21.tcpip.asc Broken Link Patch Vendor Advisory
http://www.iss.net/security_center/static/8893.php Broken Link
http://www.osvdb.org/5232 Broken Link
http://www.securityfocus.com/bid/4539 Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*

History

26 Jan 2024, 18:55

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-401
CPE cpe:2.3:o:freebsd:freebsd:4.5:stable:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.5:release:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
References (XF) http://www.iss.net/security_center/static/8893.php - (XF) http://www.iss.net/security_center/static/8893.php - Broken Link
References (BID) http://www.securityfocus.com/bid/4539 - Patch, Vendor Advisory (BID) http://www.securityfocus.com/bid/4539 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References (FREEBSD) ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:21.tcpip.asc - Patch, Vendor Advisory (FREEBSD) ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:21.tcpip.asc - Broken Link, Patch, Vendor Advisory
References (OSVDB) http://www.osvdb.org/5232 - (OSVDB) http://www.osvdb.org/5232 - Broken Link

Information

Published : 2002-07-03 04:00

Updated : 2024-02-04 16:31


NVD link : CVE-2002-0574

Mitre link : CVE-2002-0574

CVE.ORG link : CVE-2002-0574


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-401

Missing Release of Memory after Effective Lifetime