sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN20930118/ | third party advisory |
https://cgit.freebsd.org/src/commit/?id=4dc630cdd2f7a790604d2724ecb19c6aa95130a7 | mailing list patch vendor advisory |