CVE-2014-3951
The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function.
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2014-5384 is used for the NULL pointer dereference.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- freebsd/freebsd · netbsd/netbsd
- Source
- cve@mitre.org
References
- http://mail-index.netbsd.org/source-changes/2014/06/24/msg055822.html
- http://www.freebsd.org/security/advisories/FreeBSD-SA-14:15.iconv.ascVendor Advisory
- http://www.securitytracker.com/id/1030458
- http://mail-index.netbsd.org/source-changes/2014/06/24/msg055822.html
- http://www.freebsd.org/security/advisories/FreeBSD-SA-14:15.iconv.ascVendor Advisory
- http://www.securitytracker.com/id/1030458
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.