Lucene search

K
cve[email protected]CVE-2013-5209
HistoryAug 29, 2013 - 12:07 p.m.

CVE-2013-5209

2013-08-2912:07:56
CWE-200
web.nvd.nist.gov
23
sctp
freebsd
cve-2013-5209
vulnerability
kernel
information security
nvd

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.7%

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.

Affected configurations

NVD
Node
freebsdfreebsdMatch8.3
OR
freebsdfreebsdMatch9.0
OR
freebsdfreebsdMatch9.1
OR
freebsdfreebsdMatch9.1p4
OR
freebsdfreebsdMatch9.1p5
OR
freebsdfreebsdMatch9.2prerelease

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.7%