First published: Thu Aug 21 2014(Updated: )
The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2014-5384 is used for the NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =10.0 | |
NetBSD current |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3951 has a severity that can lead to denial of service due to a NULL pointer dereference.
To fix CVE-2014-3951, you should apply the latest patches from FreeBSD or NetBSD that address this vulnerability.
CVE-2014-3951 affects FreeBSD version 10.0 before p6 and NetBSD due to a flaw in the iconv implementation.
CVE-2014-3951 allows context-dependent attackers to execute a denial of service attack through a crafted argument to the iconv_open function.
Yes, CVE-2014-3951 can be exploited remotely by attackers who can provide crafted inputs to the vulnerable function.