CVE Database
/

CVE-2008-4113

Back to search

CVE-2008-4113

Published: Sep 16, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.

VendorProductVersions

n/a

n/a

affected
n/a

References

1021000
vdb-entry
x_refsource_SECTRACK
32190
third-party-advisory
x_refsource_SECUNIA
4266
third-party-advisory
x_refsource_SREASON
DSA-1655
vendor-advisory
x_refsource_DEBIAN
32393
third-party-advisory
x_refsource_SECUNIA
7618
exploit
x_refsource_EXPLOIT-DB
31121
vdb-entry
x_refsource_BID
USN-659-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SA:2008:053
vendor-advisory
x_refsource_SUSE
RHSA-2008:0857
vendor-advisory
x_refsource_REDHAT
32315
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now