VDB
CVE-2002-2185
CVE-2002-2185
PUBLISHED
CVSS 4.900000095367432 MEDIUM
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
EPSS 2.49% · 83.1th percentile
Risk Scores
CVSS 2.0
4.900000095367432
EPSS Score
2.49%
83.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | linux_advanced_workstation | 2.1, 2.1 |
| microsoft | windows_xp | |
| microsoft | windows_98 | |
| suse | suse_linux | 6.4, 6.4, 6.4 |
| n/a | n/a | * |
| redhat | enterprise_linux | 3.0, 4.0, 4.0 |
| microsoft | windows_98se | |
| redhat | linux | 6.2, 6.2, 7.0 |
| redhat | enterprise_linux_desktop | 4.0, 3.0 |
| debian | debian_linux | 2.2, 2.2, 2.2 |
| mandrakesoft | mandrake_linux | 8.0, 8.2, 8.0 |
| sgi | irix | 6.5.13, 6.5.12, 6.5.11 |
Timeline
- Dec 31, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- RHSA-2006:0140 vendor-advisory
- oval:org.mitre.oval:def:10736 vdb
- RHSA-2006:0101 vendor-advisory
- FLSA:157459-3 vendor-advisory
- 18562 third-party-advisory
- 18684 third-party-advisory
- 20020901-01-A vendor-advisory
- FLSA:157459-1 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-2185 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9436 url
- http://www.cs.ucsb.edu/~krishna/igmp_dos url
- http://www.securityfocus.com/archive/1/428058/100/0/threaded url
- http://secunia.com/advisories/18510 patch
- http://www.redhat.com/support/errata/RHSA-2006-0190.html patch
- http://www.securityfocus.com/archive/1/427981/100/0/threaded technical
- http://www.securityfocus.com/bid/5020 exploit
- http://online.securityfocus.com/archive/1/276968 technical
- http://www.cs.ucsb.edu/~krishna/igmp_dos/ exploit
- http://www.redhat.com/support/errata/RHSA-2006-0191.html patch