Lucene search

K
cveRedhatCVE-2008-3526
HistoryAug 27, 2008 - 8:41 p.m.

CVE-2008-3526

2008-08-2720:41:00
CWE-189
redhat
web.nvd.nist.gov
41
cve-2008-3526
integer overflow
sctp
denial of service
linux kernel
remote attackers

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6

Confidence

High

EPSS

0.088

Percentile

94.7%

Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option.

Affected configurations

Nvd
Node
linuxlinux_kernelMatch2.6.24
OR
linuxlinux_kernelMatch2.6.24rc2
OR
linuxlinux_kernelMatch2.6.24rc3
OR
linuxlinux_kernelMatch2.6.24.1
OR
linuxlinux_kernelMatch2.6.24.2
OR
linuxlinux_kernelMatch2.6.24.3
OR
linuxlinux_kernelMatch2.6.24.4
OR
linuxlinux_kernelMatch2.6.24.5
OR
linuxlinux_kernelMatch2.6.24.6
OR
linuxlinux_kernelMatch2.6.24.7
OR
linuxlinux_kernelMatch2.6.24_rc1
OR
linuxlinux_kernelMatch2.6.24_rc4
OR
linuxlinux_kernelMatch2.6.24_rc5
OR
linuxlinux_kernelMatch2.6.25
OR
linuxlinux_kernelMatch2.6.25.1
OR
linuxlinux_kernelMatch2.6.25.2
OR
linuxlinux_kernelMatch2.6.25.3
OR
linuxlinux_kernelMatch2.6.25.4
OR
linuxlinux_kernelMatch2.6.25.5
OR
linuxlinux_kernelMatch2.6.25.6
OR
linuxlinux_kernelMatch2.6.25.7
OR
linuxlinux_kernelMatch2.6.25.8
OR
linuxlinux_kernelMatch2.6.25.9
OR
linuxlinux_kernelMatch2.6.25.10
OR
linuxlinux_kernelMatch2.6.25.11
OR
linuxlinux_kernelMatch2.6.25.12
OR
linuxlinux_kernelMatch2.6.25.13
OR
linuxlinux_kernelMatch2.6.25.14
OR
linuxlinux_kernelMatch2.6.25.15
OR
linuxlinux_kernelMatch2.6.26
OR
linuxlinux_kernelMatch2.6.26.1
OR
linuxlinux_kernelMatch2.6.26.2
OR
linuxlinux_kernelMatch2.6.26.3
VendorProductVersionCPE
linuxlinux_kernel2.6.24cpe:2.3:o:linux:linux_kernel:2.6.24:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:*
linuxlinux_kernel2.6.24cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:*
linuxlinux_kernel2.6.24.1cpe:2.3:o:linux:linux_kernel:2.6.24.1:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.2cpe:2.3:o:linux:linux_kernel:2.6.24.2:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.3cpe:2.3:o:linux:linux_kernel:2.6.24.3:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.4cpe:2.3:o:linux:linux_kernel:2.6.24.4:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.5cpe:2.3:o:linux:linux_kernel:2.6.24.5:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.6cpe:2.3:o:linux:linux_kernel:2.6.24.6:*:*:*:*:*:*:*
linuxlinux_kernel2.6.24.7cpe:2.3:o:linux:linux_kernel:2.6.24.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6

Confidence

High

EPSS

0.088

Percentile

94.7%