CVE-2019-5597
Summary
| CVE | CVE-2019-5597 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-15 16:29:00 UTC |
| Updated | 2019-06-11 23:29:00 UTC |
| Description | In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Freebsd | Freebsd | 11.2 | - | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p2 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p3 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p4 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p5 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p6 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p7 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p9 | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | - | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | p1 | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | p3 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | - | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p2 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p3 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p4 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p5 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p6 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p7 | All | All |
| Operating System | Freebsd | Freebsd | 11.2 | p9 | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | - | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | p1 | All | All |
| Operating System | Freebsd | Freebsd | 12.0 | p3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| May 2019 FreeBSD Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| FreeBSD Multiple Security Bypass Vulnerabilities | BID | www.securityfocus.com | |
| security.FreeBSD.org/advisories/FreeBSD-SA-19:05.pf.asc | MISC | security.FreeBSD.org | Patch, Vendor Advisory |
| FreeBSD Security Advisory - FreeBSD-SA-19:05.pf ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| www.synacktiv.com/ressources/Synacktiv_OpenBSD_PacketFilter_CVE-2019-5597_ipv6_... | MISC | www.synacktiv.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.