sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-10-15 13:07
Updated : 2017-09-28 18:32
NVD link : CVE-2008-4576
Mitre link : CVE-2008-4576
JSON object : View
CWE
Products Affected
linux
- linux_kernel