Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1573

Опубликовано: 02 фев. 2012
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 2.6.34 (исключая)

EPSS

Процентиль: 72%
0.00751
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 13 лет назад

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.

redhat
около 15 лет назад

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.

CVSS3: 5.9
debian
больше 13 лет назад

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip ...

CVSS3: 5.9
github
около 3 лет назад

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.

oracle-oval
около 14 лет назад

ELSA-2011-2015: Oracle Linux 6 Unbreakable Enterprise kernel security fix update (IMPORTANT)

EPSS

Процентиль: 72%
0.00751
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-682
Уязвимость CVE-2011-1573