CVE-2014-0101
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD
Description
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Affected (35)
Products: Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Canonical: Ubuntu Linux · +1 more
Show all products
Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Canonical: Ubuntu Linux · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Edge Gateway, Big Ip Enterprise Manager, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Protocol Security Module, Big Ip Wan Optimization Manager, Big Ip Webaccelerator, Big Iq Adc, Big Iq Centralized Management, Big Iq Cloud, Big Iq Device, Big Iq Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.6.24 to 3.2.56 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.3 | |
| Version 6.0 | |
| Version 6.4 | |
| Version 6.5 | |
| Version 6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.1.0 to 11.5.3 | |
| From 11.3.0 to 11.5.3 | |
| From 11.1.0 to 11.5.3 | |
| From 11.4.0 to 11.5.3 | |
| From 11.1.0 to 11.5.3 | |
| From 11.1.0 to 11.3.0 | |
| From 2.1.0 to 2.3.0 | |
| From 11.1.0 to 11.5.3 | |
| From 11.1.0 to 11.5.3 | |
| From 11.1.0 to 11.5.3 | |
| From 11.3.0 to 11.5.3 | |
| From 11.1.0 to 11.4.1 | |
| From 11.1.0 to 11.3.0 | |
| From 11.1.0 to 11.3.0 | |
| Version 4.5.0 | |
| Version 4.6.0 | |
| From 4.0.0 to 4.5.0 | |
| From 4.2.0 to 4.5.0 | |
| From 4.0.0 to 4.5.0 |
Related CWEs
References (24)
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListPatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.