Tracker / CVE-2014-0101
CVE-2014-0101
Alta 7.8
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Prodotti e versioni affette
| canonical | ubuntu_linux |
|---|---|
| f5 | big-ip_access_policy_manager · 11.1.0 → 11.5.3 |
| f5 | big-ip_advanced_firewall_manager · 11.3.0 → 11.5.3 |
| f5 | big-ip_analytics · 11.1.0 → 11.5.3 |
| f5 | big-ip_application_acceleration_manager · 11.4.0 → 11.5.3 |
| f5 | big-ip_application_security_manager · 11.1.0 → 11.5.3 |
| f5 | big-ip_edge_gateway · 11.1.0 → 11.3.0 |
| f5 | big-ip_enterprise_manager · 2.1.0 → 2.3.0 |
| f5 | big-ip_enterprise_manager · 3.0.0 → 3.1.1 |
| f5 | big-ip_global_traffic_manager · 11.1.0 → 11.5.3 |
| f5 | big-ip_link_controller · 11.1.0 → 11.5.3 |
| f5 | big-ip_local_traffic_manager · 11.1.0 → 11.5.3 |
| f5 | big-ip_policy_enforcement_manager · 11.3.0 → 11.5.3 |
| f5 | big-ip_protocol_security_module · 11.1.0 → 11.4.1 |
| f5 | big-ip_wan_optimization_manager · 11.1.0 → 11.3.0 |
| f5 | big-ip_webaccelerator · 11.1.0 → 11.3.0 |
| f5 | big-iq_adc |
| f5 | big-iq_centralized_management |
| f5 | big-iq_cloud · 4.0.0 → 4.5.0 |
| f5 | big-iq_device · 4.2.0 → 4.5.0 |
| f5 | big-iq_security · 4.0.0 → 4.5.0 |
| linux | linux_kernel · 2.6.24 → 3.2.56 |
| linux | linux_kernel · 3.11 → 3.12.15 |
| linux | linux_kernel · 3.13 → 3.13.7 |
| linux | linux_kernel · 3.3 → 3.4.84 |
| linux | linux_kernel · 3.5 → 3.10.34 |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_workstation |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.