← Back

CVE-2019-5598

nvd nist
Published: May 15, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if the outer ICMP or ICMP6 packet has the same destination IP as the source IP of the inner protocol packet allowing a maliciously crafted ICMP/ICMP6 packet could bypass the packet filter rules and be passed to a host that would otherwise be unavailable.

Affected (12)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.2
Version 11.2 p2
Version 11.2 p3
Version 11.2 p4
Version 11.2 p5
Version 11.2 p6
Version 11.2 p7
Version 11.2 p9
Version 11.2 rc3
Version 12.0
Version 12.0 p1
Version 12.0 p3

References (13)

Source: secteam@freebsd.org
Source: secteam@freebsd.org
PatchVendor Advisory
Source: secteam@freebsd.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.