CVE-2014-8475: Medium severity freebsd kernel vulnerability
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8475?
CVE-2014-8475 has a severity rating that indicates a denial of service vulnerability impacting affected FreeBSD versions.
How do I fix CVE-2014-8475?
To fix CVE-2014-8475, upgrade to a patched version of FreeBSD that addresses the library ordering issue in OpenSSH.
Which versions of FreeBSD are affected by CVE-2014-8475?
CVE-2014-8475 affects FreeBSD versions 9.1, 9.2, and 10.0 when compiling OpenSSH with Kerberos support.
What are the potential impacts of CVE-2014-8475?
The potential impacts of CVE-2014-8475 include a denial of service that can cause sshd to deadlock and prevent new connections.
How can remote attackers exploit CVE-2014-8475?
Remote attackers can exploit CVE-2014-8475 by sending multiple connections to the sshd service, leading to a deadlock.