CVE-2008-4576
CVE-2008-4576
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.18http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://permalink.gmane.org/gmane.comp.security.oss.general/1039http://secunia.com/advisories/32370http://secunia.com/advisories/32386http://secunia.com/advisories/32759http://secunia.com/advisories/32918http://secunia.com/advisories/32998http://secunia.com/advisories/33180http://secunia.com/advisories/33182