CVE-2013-3077
Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass intended restrictions on kernel-memory read and write operations, and consequently gain privileges, via vectors involving a large number of source-filter entries.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- freebsd/freebsd
- Source
- cve@mitre.org
References
- http://svnweb.freebsd.org/base?view=revision&revision=254629Patch
- http://www.freebsd.org/security/advisories/FreeBSD-SA-13:09.ip_multicast.ascVendor Advisory
- http://svnweb.freebsd.org/base?view=revision&revision=254629Patch
- http://www.freebsd.org/security/advisories/FreeBSD-SA-13:09.ip_multicast.ascVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.