CVE-2002-2185
published 2002-12-31CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
2.49%
82.9th percentile
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| hp | secure_web_server_for_tru64 | — | — |
| hp | secure_web_server_for_tru64 | — | — |
| hp | secure_web_server_for_tru64 | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux_advanced_workstation | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
| sgi | irix | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rp7-7c38-2w9q: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet add
ghsa_unreviewed·2022-05-03
CVE-2002-2185 [MEDIUM] GHSA-7rp7-7c38-2w9q: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet add
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
GHSA
GHSA-83x7-r93g-qwrr: Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4
ghsa_unreviewed·2022-04-30·CVSS 4.9
CVE-2002-2264 [MEDIUM] GHSA-83x7-r93g-qwrr: Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain.
Red Hat
security flaw
vendor_redhat·2002-06-25·CVSS 4.9
CVE-2002-2185 [MEDIUM] security flaw
security flaw
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2002-2185 security flaw
bugzilla·2018-08-16·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 security flaw
CVE-2002-2185 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
Bugzilla
CVE-2002-2185 IGMP DoS
bugzilla·2005-12-02·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 IGMP DoS
CVE-2002-2185 IGMP DoS
+++ This bug was initially created as a clone of Bug #174807 +++
http://www.cs.ucsb.edu/~krishna/igmp_dos/
With IGMP version 1 and 2 it is possible to inject a unicast report to a client
which will make it ignore multicast reports sent later by the router.
The fix is to only accept the report if is was sent to a multicast or unicast
address. Fix from David Stevens at IBM and will be made upstream shortly.
-- Additional comment from [email protected] on 2005-12-02 08:53 EST --
Created an attachment (id=121751)
proposed upstream patch
Discussion:
*** Bug 174809 has been marked as a duplicate of this bug. ***
---
A fix for this problem has just been committed to the RHEL3 E7
patch pool this evening (in kernel version 2.4.21-37.0.1.EL).
---
An advisory has been i
Bugzilla
CVE-2002-2185 IGMP DoS
bugzilla·2005-12-02·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 IGMP DoS
CVE-2002-2185 IGMP DoS
+++ This bug was initially created as a clone of Bug #174807 +++
http://www.cs.ucsb.edu/~krishna/igmp_dos/
With IGMP version 1 and 2 it is possible to inject a unicast report to a client
which will make it ignore multicast reports sent later by the router.
The fix is to only accept the report if is was sent to a multicast or unicast
address. Fix from David Stevens at IBM and will be made upstream shortly.
-- Additional comment from [email protected] on 2005-12-02 08:53 EST --
Created an attachment (id=121751)
proposed upstream patch
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updat
Bugzilla
CVE-2002-2185 IGMP DoS (ipf)
bugzilla·2005-12-02·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 IGMP DoS (ipf)
CVE-2002-2185 IGMP DoS (ipf)
+++ This bug was initially created as a clone of Bug #174807 +++
http://www.cs.ucsb.edu/~krishna/igmp_dos/
With IGMP version 1 and 2 it is possible to inject a unicast report to a client
which will make it ignore multicast reports sent later by the router.
The fix is to only accept the report if is was sent to a multicast or unicast
address. Fix from David Stevens at IBM and will be made upstream shortly.
-- Additional comment from [email protected] on 2005-12-02 08:53 EST --
Created an attachment (id=121751)
proposed upstream patch
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the
Bugzilla
CVE-2002-2185 IGMP DoS
bugzilla·2005-12-02·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 IGMP DoS
CVE-2002-2185 IGMP DoS
http://www.cs.ucsb.edu/~krishna/igmp_dos/
With IGMP version 1 and 2 it is possible to inject a unicast report to a client
which will make it ignore multicast reports sent later by the router.
The fix is to only accept the report if is was sent to a multicast or unicast
address. Fix from David Stevens at IBM and will be made upstream shortly.
Discussion:
Created attachment 121751
proposed upstream patch
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errat
Bugzilla
CVE-2002-2185 IGMP DoS
bugzilla·2005-12-02·CVSS 4.9
CVE-2002-2185 [MEDIUM] CVE-2002-2185 IGMP DoS
CVE-2002-2185 IGMP DoS
+++ This bug was initially created as a clone of Bug #174807 +++
http://www.cs.ucsb.edu/~krishna/igmp_dos/
With IGMP version 1 and 2 it is possible to inject a unicast report to a client
which will make it ignore multicast reports sent later by the router.
The fix is to only accept the report if is was sent to a multicast or unicast
address. Fix from David Stevens at IBM and will be made upstream shortly.
-- Additional comment from [email protected] on 2005-12-02 08:53 EST --
Created an attachment (id=121751)
proposed upstream patch
Discussion:
This is apparently an accidental dup entry of bug 174808.
*** This bug has been marked as a duplicate of 174808 ***
Bugzilla
Multiple Kernel vulnerabilities
bugzilla·2005-05-11
[MEDIUM] Multiple Kernel vulnerabilities
Multiple Kernel vulnerabilities
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Mozilla rulez!)
Description of problem:
Paul Starzetz of iSEC has found yet another bug in binfmt_elf.c. It can be abused to crash the kernel, perhaps even to break into the kernel land. See the advisory for details.
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Steps to Reproduce:
Additional info:
I've got a quick and dirty patch. I'll submit it ASAP.
Discussion:
Grr...Bugzilla assigned the bug to [email protected] rather than to
[email protected]
---
Created attachment 114264
The patch for CAN-2005-1263
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
This patch can be applied to FL kernel 2.4.20-43:
402e548b02382c015d6f5e5704370a1ba546598b
li
ftp://patches.sgi.com/support/free/security/advisories/20020901-01-Ahttp://online.securityfocus.com/archive/1/276968http://secunia.com/advisories/18510http://secunia.com/advisories/18562http://secunia.com/advisories/18684http://www.cs.ucsb.edu/~krishna/igmp_dos/http://www.redhat.com/support/errata/RHSA-2006-0101.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0140.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0191.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/archive/1/427981/100/0/threadedhttp://www.securityfocus.com/archive/1/428028/100/0/threadedhttp://www.securityfocus.com/archive/1/428058/100/0/threadedhttp://www.securityfocus.com/bid/5020https://exchange.xforce.ibmcloud.com/vulnerabilities/9436https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10736ftp://patches.sgi.com/support/free/security/advisories/20020901-01-Ahttp://online.securityfocus.com/archive/1/276968http://secunia.com/advisories/18510http://secunia.com/advisories/18562http://secunia.com/advisories/18684http://www.cs.ucsb.edu/~krishna/igmp_dos/http://www.redhat.com/support/errata/RHSA-2006-0101.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0140.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0190.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0191.htmlhttp://www.securityfocus.com/archive/1/427980/100/0/threadedhttp://www.securityfocus.com/archive/1/427981/100/0/threadedhttp://www.securityfocus.com/archive/1/428028/100/0/threadedhttp://www.securityfocus.com/archive/1/428058/100/0/threadedhttp://www.securityfocus.com/bid/5020https://exchange.xforce.ibmcloud.com/vulnerabilities/9436https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10736
2002-12-31
Published