Double Free in Cisco Firewall Threat Defense (FTD) - CVE-2020-3179
Published: May 7, 2020
Cisco Firewall Threat Defense (FTD)
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a memory handling error when the generic routing encapsulation (GRE) over IPv6 traffic is processed. A remote attacker can send a specially crafted GRE over IPv6 packets with either IPv4 or IPv6 payload, trigger double free error and cause a denial of service condition on the target system.