vendor:
FreeBSD
by:
Shaun Colley
7,2
CVSS
HIGH
DoS (Denial of Service)
399
CWE
Product Name: FreeBSD
Affected Version From: 7.2-RELEASE
Affected Version To: 7.2-RELEASE
Patch Exists: NO
Related CWE: N/A
CPE: o:freebsd:freebsd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2009
FreeBSD 7.2-RELEASE SCTP Local Kernel DoS
This exploit is based on an unfixed bug found in FreeBSD 7.2-RELEASE. It is a local kernel DoS (kern panic) exploit which is only tested on 7.2-RELEASE, but probably older and newer builds are vulnerable as well. The exploit uses a socket connection to send a malicious packet to the target system, which causes a kernel panic.
Mitigation:
The bug has not been fixed yet, so the only way to mitigate this vulnerability is to upgrade to a newer version of FreeBSD.