Beveiligingsadvies

CVE-2008-4576

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2008-10-15 19:00:00
Laatst bijgewerkt 2024-08-07 10:24:20
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.