Back to search
CVE-2014-0101
Published: Mar 11, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
65943
vdb-entry
x_refsource_BID
http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15317.html
x_refsource_CONFIRM
RHSA-2014:0328
vendor-advisory
x_refsource_REDHAT
USN-2173-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0432
vendor-advisory
x_refsource_REDHAT
USN-2174-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0419
vendor-advisory
x_refsource_REDHAT
59216
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=1070705
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now