{"api_version":"1","generated_at":"2026-07-23T09:36:19+00:00","cve":"CVE-2014-8475","urls":{"html":"https://cve.report/CVE-2014-8475","api":"https://cve.report/api/cve/CVE-2014-8475.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8475","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8475"},"summary":{"title":"CVE-2014-8475","description":"FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-11-18 15:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-17","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html","name":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FreeBSD Security Advisory - sshd Denial Of Service ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc","name":"https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/61440","name":"http://secunia.com/advisories/61440","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA61440 - FreeBSD sshd Denial of Service Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031168","name":"http://www.securitytracker.com/id/1031168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FreeBSD OpenSSH Child Process Deadlock Lets Remote Users Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/70913","name":"http://www.securityfocus.com/bid/70913","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FreeBSD CVE-2014-8475 Remote Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98491","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8475","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8475","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:18:48.347Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"FreeBSD-SA-14:24","tags":["vendor-advisory","x_refsource_FREEBSD","x_transferred"],"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html"},{"name":"freebsd-cve20148475-dos(98491)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98491"},{"name":"61440","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/61440"},{"name":"70913","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/70913"},{"name":"1031168","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031168"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-11-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"FreeBSD-SA-14:24","tags":["vendor-advisory","x_refsource_FREEBSD"],"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html"},{"name":"freebsd-cve20148475-dos(98491)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98491"},{"name":"61440","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/61440"},{"name":"70913","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/70913"},{"name":"1031168","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031168"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-8475","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"FreeBSD-SA-14:24","refsource":"FREEBSD","url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A24.sshd.asc"},{"name":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/128972/FreeBSD-Security-Advisory-sshd-Denial-Of-Service.html"},{"name":"freebsd-cve20148475-dos(98491)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98491"},{"name":"61440","refsource":"SECUNIA","url":"http://secunia.com/advisories/61440"},{"name":"70913","refsource":"BID","url":"http://www.securityfocus.com/bid/70913"},{"name":"1031168","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031168"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-8475","datePublished":"2014-11-18T15:00:00.000Z","dateReserved":"2014-10-24T00:00:00.000Z","dateUpdated":"2024-08-06T13:18:48.347Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-11-18 15:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-17","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:9.1:*:*:*:*:*:*:*","matchCriteriaId":"D78E559A-430D-4D50-8A83-58A37D393471"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:9.2:*:*:*:*:*:*:*","matchCriteriaId":"2C560926-7789-4052-819D-C36C43C9C61E"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*","matchCriteriaId":"CA79CE41-D873-4A4A-A20C-83EB8772E5FA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8475","Ordinal":"1","Title":"CVE-2014-8475","CVE":"CVE-2014-8475","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8475","Ordinal":"1","NoteData":"FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.","Type":"Description","Title":"CVE-2014-8475"},{"CveYear":"2014","CveId":"8475","Ordinal":"2","NoteData":"2014-11-18","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8475","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}