Vulnerability Description
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sgi | Irix | 6.5 |
| Debian | Debian Linux | 2.2 |
| Mandrakesoft | Mandrake Linux | 8.0 |
| Microsoft | Windows 98 | All versions |
| Microsoft | Windows 98Se | All versions |
| Microsoft | Windows Xp | All versions |
| Redhat | Enterprise Linux | 3.0 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Linux | 6.2 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Suse | Suse Linux | 6.4 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20020901-01-A
- http://online.securityfocus.com/archive/1/276968
- http://secunia.com/advisories/18510PatchVendor Advisory
- http://secunia.com/advisories/18562PatchVendor Advisory
- http://secunia.com/advisories/18684PatchVendor Advisory
- http://www.cs.ucsb.edu/~krishna/igmp_dos/ExploitPatch
- http://www.redhat.com/support/errata/RHSA-2006-0101.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2006-0140.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2006-0190.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2006-0191.htmlPatch
- http://www.securityfocus.com/archive/1/427980/100/0/threaded
- http://www.securityfocus.com/archive/1/427981/100/0/threaded
- http://www.securityfocus.com/archive/1/428028/100/0/threaded
- http://www.securityfocus.com/archive/1/428058/100/0/threaded
- http://www.securityfocus.com/bid/5020ExploitPatch
FAQ
What is CVE-2002-2185?
CVE-2002-2185 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which...
How severe is CVE-2002-2185?
CVE-2002-2185 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2185?
Check the references section above for vendor advisories and patch information. Affected products include: Sgi Irix, Debian Debian Linux, Mandrakesoft Mandrake Linux, Microsoft Windows 98, Microsoft Windows 98Se.