net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.
http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.34
http://openwall.com/lists/oss-security/2011/04/11/12
http://openwall.com/lists/oss-security/2011/04/11/4
Source: MITRE
Published: 2012-02-02
Updated: 2020-08-04
Type: CWE-682
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 5.9
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.2
Severity: MEDIUM
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
89105 | VMware ESX / ESXi Service Console and Third-Party Libraries Multiple Vulnerabilities (VMSA-2012-0001) (remote check) | Nessus | Misc. | high |
79507 | OracleVM 2.2 : kernel (OVMSA-2013-0039) | Nessus | OracleVM Local Security Checks | critical |
68416 | Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2011-2015) | Nessus | Oracle Linux Local Security Checks | high |
68304 | Oracle Linux 5 : kernel (ELSA-2011-0927) | Nessus | Oracle Linux Local Security Checks | medium |
68273 | Oracle Linux 6 : kernel (ELSA-2011-0498) | Nessus | Oracle Linux Local Security Checks | high |
61083 | Scientific Linux Security Update : kernel on SL5.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | medium |
61035 | Scientific Linux Security Update : kernel on SL6.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | high |
59156 | SuSE 10 Security Update : Linux kernel (ZYPP Patch Number 7515) | Nessus | SuSE Local Security Checks | high |
57749 | VMSA-2012-0001 : VMware ESXi and ESX updates to third-party library and ESX Service Console | Nessus | VMware ESX Local Security Checks | high |
57212 | SuSE 10 Security Update : Linux kernel (ZYPP Patch Number 7516) | Nessus | SuSE Local Security Checks | high |
56768 | Ubuntu 10.04 LTS : linux-lts-backport-natty vulnerabilities (USN-1256-1) | Nessus | Ubuntu Local Security Checks | critical |
56640 | USN-1241-1 : linux-fsl-imx51 vulnerabilities | Nessus | Ubuntu Local Security Checks | critical |
56583 | Ubuntu 8.04 LTS : linux vulnerabilities (USN-1236-1) | Nessus | Ubuntu Local Security Checks | high |
55609 | CentOS 5 : kernel (CESA-2011:0927) | Nessus | CentOS Local Security Checks | medium |
55597 | RHEL 5 : kernel (RHSA-2011:0927) | Nessus | Red Hat Local Security Checks | medium |
55589 | Ubuntu 10.10 : linux-mvl-dove vulnerabilities (USN-1159-1) | Nessus | Ubuntu Local Security Checks | high |
55521 | Ubuntu 10.04 LTS : linux-mvl-dove vulnerabilities (USN-1162-1) | Nessus | Ubuntu Local Security Checks | high |
55468 | SuSE 10 Security Update : Linux kernel (ZYPP Patch Number 7568) | Nessus | SuSE Local Security Checks | high |
55104 | Ubuntu 10.04 LTS : linux, linux-ec2 vulnerabilities (USN-1141-1) | Nessus | Ubuntu Local Security Checks | high |
53867 | RHEL 6 : kernel (RHSA-2011:0498) | Nessus | Red Hat Local Security Checks | high |
53571 | SuSE 11.1 Security Update : Linux kernel (SAT Patch Number 4376) | Nessus | SuSE Local Security Checks | high |
53570 | SuSE 11.1 Security Update : Linux kernel (SAT Patch Numbers 4384 / 4386) | Nessus | SuSE Local Security Checks | high |
801507 | CentOS RHSA-2011-0927 Security Check | Log Correlation Engine | Generic | high |