Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3673

Опубликовано: 09 окт. 2014
Источник: redhat
CVSS2: 7.1
EPSS Низкий

Описание

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

A flaw was found in the way the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation handled malformed Address Configuration Change Chunks (ASCONF). A remote attacker could use either of these flaws to crash the system.

Отчет

This issue does affect Red Hat Enterprise Linux 5. This has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. This issue does affect Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG. Future Linux kernel updates for the respective releases will address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise MRG 2realtime-kernelAffected
Red Hat Enterprise Linux 6kernelFixedRHSA-2014:199716.12.2014
Red Hat Enterprise Linux 6.2 Advanced Update SupportkernelFixedRHSA-2015:011503.02.2015
Red Hat Enterprise Linux 6.4 Extended Update SupportkernelFixedRHSA-2015:004313.01.2015
Red Hat Enterprise Linux 6.5 Extended Update SupportkernelFixedRHSA-2015:006220.01.2015
Red Hat Enterprise Linux 7kernelFixedRHSA-2014:197109.12.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1147850kernel: sctp: skb_over_panic when receiving malformed ASCONF chunks

EPSS

Процентиль: 93%
0.09797
Низкий

7.1 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 10 лет назад

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

CVSS3: 7.5
nvd
больше 10 лет назад

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

CVSS3: 7.5
debian
больше 10 лет назад

The SCTP implementation in the Linux kernel through 3.17.2 allows remo ...

CVSS3: 7.5
github
около 3 лет назад

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

oracle-oval
больше 10 лет назад

ELSA-2014-3089: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 93%
0.09797
Низкий

7.1 High

CVSS2