VDB
CVE-2002-2185
CVE-2002-2185
PUBLISHED
CVSS 4.900000095367432 MEDIUM
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
EPSS 2.49% · 84.1th percentile
Risk Scores
CVSS 2.0
4.900000095367432
EPSS Score
2.49%
84.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | linux_advanced_workstation | 2.1, 2.1 |
| microsoft | windows_xp | |
| microsoft | windows_98 | |
| suse | suse_linux | 6.4, 6.4, 6.4 |
| n/a | n/a | * |
| redhat | enterprise_linux | 3.0, 4.0, 4.0 |
| microsoft | windows_98se | |
| redhat | linux | 6.2, 6.2, 7.0 |
| redhat | enterprise_linux_desktop | 4.0, 3.0 |
| debian | debian_linux | 2.2, 2.2, 2.2 |
| mandrakesoft | mandrake_linux | 8.0, 8.2, 8.0 |
| sgi | irix | 6.5.13, 6.5.12, 6.5.11 |
Timeline
- Dec 31, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
References
- RHSA-2006:0140 vendor-advisory
- oval:org.mitre.oval:def:10736 vdb
- RHSA-2006:0101 vendor-advisory
- FLSA:157459-3 vendor-advisory
- 18562 third-party-advisory
- 18684 third-party-advisory
- 20020901-01-A vendor-advisory
- FLSA:157459-1 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-2185 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9436 url
- http://www.cs.ucsb.edu/~krishna/igmp_dos url
- http://www.securityfocus.com/archive/1/428058/100/0/threaded url
- http://secunia.com/advisories/18510 patch
- http://www.redhat.com/support/errata/RHSA-2006-0190.html patch
- http://www.securityfocus.com/archive/1/427981/100/0/threaded technical
- http://www.securityfocus.com/bid/5020 exploit
- http://online.securityfocus.com/archive/1/276968 technical
- http://www.cs.ucsb.edu/~krishna/igmp_dos/ exploit
- http://www.redhat.com/support/errata/RHSA-2006-0191.html patch