7.8

CVE-2010-3432

The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.35.6
OpensuseOpensuse Version11.3
SuseLinux Enterprise Real Time Extension Version11 Updatesp1
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version10.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.32% 0.878
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=linux-netdev&m=128453869227715&w=3
Patch
Third Party Advisory
Mailing List
http://marc.info/?l=oss-security&m=128534569803598&w=2
Patch
Third Party Advisory
Mailing List
http://marc.info/?l=oss-security&m=128537701808336&w=2
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/43480
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=637675
Third Party Advisory
Issue Tracking