CVE-2015-1414: Debian Linux

High severity, CVSS 7.8. EPSS: 4.2% chance of exploitation in the next 30 days.

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Freebsd Freebsd: version 8.4 only; version 9.0 only; version 9.1 only; version 9.2 only; version 9.3 only; version 10.0 only; …
  • Netgate Pfsense: version 2.2.1 only

Published 2015-02-27. Last modified 2026-06-17.