Lucene search

K
cve[email protected]CVE-2014-1453
HistoryApr 16, 2014 - 6:37 p.m.

CVE-2014-1453

2014-04-1618:37:13
CWE-399
web.nvd.nist.gov
26
nfs server
freebsd
denial of service
deadlock
cve-2014-1453

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.5%

The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involving a thread that uses the correct locking order.

Affected configurations

NVD
Node
freebsdfreebsdMatch8.3
OR
freebsdfreebsdMatch8.4
OR
freebsdfreebsdMatch9.0
OR
freebsdfreebsdMatch9.0beta1
OR
freebsdfreebsdMatch9.0beta2
OR
freebsdfreebsdMatch9.0beta3
OR
freebsdfreebsdMatch9.1
OR
freebsdfreebsdMatch9.1p4
OR
freebsdfreebsdMatch9.1p5
OR
freebsdfreebsdMatch9.2
OR
freebsdfreebsdMatch9.2prerelease
OR
freebsdfreebsdMatch9.2rc1
OR
freebsdfreebsdMatch9.2rc2
OR
freebsdfreebsdMatch10.0

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.5%