4.7

CVE-2008-4445

Exploit

The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bounds established by SCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function, a different vulnerability than CVE-2008-4113.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.25.14
LinuxLinux Kernel Version2.2.27
LinuxLinux Kernel Version2.4.36
LinuxLinux Kernel Version2.4.36.1
LinuxLinux Kernel Version2.4.36.2
LinuxLinux Kernel Version2.4.36.3
LinuxLinux Kernel Version2.4.36.4
LinuxLinux Kernel Version2.4.36.5
LinuxLinux Kernel Version2.4.36.6
LinuxLinux Kernel Version2.6
LinuxLinux Kernel Version2.6.18
LinuxLinux Kernel Version2.6.18 Updaterc1
LinuxLinux Kernel Version2.6.18 Updaterc2
LinuxLinux Kernel Version2.6.18 Updaterc3
LinuxLinux Kernel Version2.6.18 Updaterc4
LinuxLinux Kernel Version2.6.18 Updaterc5
LinuxLinux Kernel Version2.6.18 Updaterc6
LinuxLinux Kernel Version2.6.18 Updaterc7
LinuxLinux Kernel Version2.6.19.4
LinuxLinux Kernel Version2.6.19.5
LinuxLinux Kernel Version2.6.19.6
LinuxLinux Kernel Version2.6.19.7
LinuxLinux Kernel Version2.6.20.16
LinuxLinux Kernel Version2.6.20.17
LinuxLinux Kernel Version2.6.20.18
LinuxLinux Kernel Version2.6.20.19
LinuxLinux Kernel Version2.6.20.20
LinuxLinux Kernel Version2.6.20.21
LinuxLinux Kernel Version2.6.21.5
LinuxLinux Kernel Version2.6.21.6
LinuxLinux Kernel Version2.6.21.7
LinuxLinux Kernel Version2.6.22
LinuxLinux Kernel Version2.6.22.2
LinuxLinux Kernel Version2.6.22.8
LinuxLinux Kernel Version2.6.22.9
LinuxLinux Kernel Version2.6.22.10
LinuxLinux Kernel Version2.6.22.11
LinuxLinux Kernel Version2.6.22.12
LinuxLinux Kernel Version2.6.22.13
LinuxLinux Kernel Version2.6.22.14
LinuxLinux Kernel Version2.6.22.15
LinuxLinux Kernel Version2.6.22.17
LinuxLinux Kernel Version2.6.22.18
LinuxLinux Kernel Version2.6.22.19
LinuxLinux Kernel Version2.6.22.20
LinuxLinux Kernel Version2.6.22.21
LinuxLinux Kernel Version2.6.22.22
LinuxLinux Kernel Version2.6.22_rc1
LinuxLinux Kernel Version2.6.22_rc7
LinuxLinux Kernel Version2.6.23
LinuxLinux Kernel Version2.6.23.8
LinuxLinux Kernel Version2.6.23.9
LinuxLinux Kernel Version2.6.23.10
LinuxLinux Kernel Version2.6.23.11
LinuxLinux Kernel Version2.6.23.12
LinuxLinux Kernel Version2.6.23.13
LinuxLinux Kernel Version2.6.23.15
LinuxLinux Kernel Version2.6.23.16
LinuxLinux Kernel Version2.6.23.17
LinuxLinux Kernel Version2.6.23_rc1
LinuxLinux Kernel Version2.6.24
LinuxLinux Kernel Version2.6.24.1
LinuxLinux Kernel Version2.6.24.2
LinuxLinux Kernel Version2.6.24.3
LinuxLinux Kernel Version2.6.24.4
LinuxLinux Kernel Version2.6.24.5
LinuxLinux Kernel Version2.6.24.6
LinuxLinux Kernel Version2.6.24.7
LinuxLinux Kernel Version2.6.24_rc1
LinuxLinux Kernel Version2.6.24_rc4
LinuxLinux Kernel Version2.6.24_rc5
LinuxLinux Kernel Version2.6.25
LinuxLinux Kernel Version2.6.25 Editionx86_64
LinuxLinux Kernel Version2.6.25.1
LinuxLinux Kernel Version2.6.25.1 Editionx86_64
LinuxLinux Kernel Version2.6.25.2
LinuxLinux Kernel Version2.6.25.2 Editionx86_64
LinuxLinux Kernel Version2.6.25.3
LinuxLinux Kernel Version2.6.25.3 Editionx86_64
LinuxLinux Kernel Version2.6.25.4
LinuxLinux Kernel Version2.6.25.4 Editionx86_64
LinuxLinux Kernel Version2.6.25.5
LinuxLinux Kernel Version2.6.25.5 Editionx86_64
LinuxLinux Kernel Version2.6.25.6
LinuxLinux Kernel Version2.6.25.6 Editionx86_64
LinuxLinux Kernel Version2.6.25.7
LinuxLinux Kernel Version2.6.25.7 Editionx86_64
LinuxLinux Kernel Version2.6.25.8
LinuxLinux Kernel Version2.6.25.8 Editionx86_64
LinuxLinux Kernel Version2.6.25.9
LinuxLinux Kernel Version2.6.25.9 Editionx86_64
LinuxLinux Kernel Version2.6.25.10
LinuxLinux Kernel Version2.6.25.10 Editionx86_64
LinuxLinux Kernel Version2.6.25.11
LinuxLinux Kernel Version2.6.25.11 Editionx86_64
LinuxLinux Kernel Version2.6.25.12
LinuxLinux Kernel Version2.6.25.12 Editionx86_64
LinuxLinux Kernel Version2.6.25.13
LinuxLinux Kernel Version2.6.25.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.