CVE-2014-3954: Freebsd

High severity, CVSS 10.0. EPSS: 3.9% chance of exploitation in the next 30 days.

Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.

Affected products

  • Freebsd Freebsd: version 9.1 only; version 9.2 only; version 9.3 only; version 10.0 only; version 10.1 only

Published 2014-10-27. Last modified 2026-06-17.