← Back

CVE-2013-5209

nvd nist
Published: Aug 29, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.

Affected (6)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 8.3
Version 9.0
Version 9.1
Version 9.1 p4
Version 9.1 p5
Version 9.2 prerelease

References (10)

Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.