4.3

CVE-2014-8475

FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 9.1
Freebsd ≫ Freebsd Version 9.2
Freebsd ≫ Freebsd Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.747
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html
http://secunia.com/advisories/61440
http://www.securityfocus.com/bid/70913
http://www.securitytracker.com/id/1031168
https://exchange.xforce.ibmcloud.com/vulnerabilities/98491
https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc
Vendor Advisory