CVE-2014-3687

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 7.8 (High)
78% Progress
EPSS 3.12 % (91th)
3.12% Progress
Affected Products 12
Advisories 38

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

Weaknesses
CWE-400
Uncontrolled Resource Consumption
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-11-10 11:55:06
(9 years ago)
Updated Date
2023-02-13 00:41:53
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.27 version and prior 3.2.64 version cpe:2.3:o:linux:linux_kernel >= 2.6.27 < 3.2.64
  Linux Kernel from 3.3 version and prior 3.4.107 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.107
  Linux Kernel from 3.5 version and prior 3.10.61 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.10.61
  Linux Kernel from 3.11 version and prior 3.12.34 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.34
  Linux Kernel from 3.13 version and prior 3.14.25 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.25
  Linux Kernel from 3.15 version and prior 3.16.35 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.16.35
  Linux Kernel from 3.17 version and prior 3.17.4 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.17.4

Configuration #2

    CPE23 From Up To
  Redhat Enterprise Mrg 2.0 cpe:2.3:o:redhat:enterprise_mrg:2.0

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm

Configuration #4

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Novell Suse Linux Enterprise Desktop 12.0 cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0
  Novell Suse Linux Enterprise Server 12.0 cpe:2.3:o:novell:suse_linux_enterprise_server:12.0
  Opensuse Evergreen 11.4 cpe:2.3:o:opensuse:evergreen:11.4
  Suse Linux Enterprise Real Time Extension 11 SP3 cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp3
  Suse Linux Enterprise Software Development Kit 12 cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-
  Suse Linux Enterprise Workstation Extension 12 cpe:2.3:o:suse:linux_enterprise_workstation_extension:12
  Suse Linux Enterprise Server 11 SP2 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp2:*:*:ltss

Configuration #5

    CPE23 From Up To
  Oracle Linux 5 cpe:2.3:o:oracle:linux:5:-
  Oracle Linux 6 cpe:2.3:o:oracle:linux:6:-
  Oracle Linux 7 cpe:2.3:o:oracle:linux:7:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...