← Terug naar CVE-database
Beschrijving
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Vendors
Linux
Redhat
Canonical
F5
Affected products
Linux Kernel
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Ubuntu Linux
Big-ip Access Policy Manager
Big-ip Advanced Firewall Manager
Big-ip Analytics
Big-ip Application Acceleration Manager
Big-ip Application Security Manager
Big-ip Edge Gateway
Big-ip Enterprise Manager
Big-ip Global Traffic Manager
Big-ip Link Controller
Big-ip Local Traffic Manager
Big-ip Policy Enforcement Manager
Big-ip Protocol Security Module
Big-ip Wan Optimization Manager
Big-ip Webaccelerator
Big-iq Adc
Big-iq Centralized Management
Big-iq Cloud
Big-iq Device
Big-iq Security