#VU34417 Out-of-bounds read in FreeBSD - CVE-2019-15874
Published: April 29, 2020 / Updated: August 8, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results.