CVE-2010-3705

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 26 Nov 2010, 19:00
Last modified:07 Aug 2024, 03:18

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.3 HIGH
v2.0 (nvd)
EPSS Score
0.89% LOW
1% probability -0.32%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Nov 2010, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 03:18
Last Modified
Vulnerability information updated

Description

The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.

CVSS Metrics

  • v2.0HIGHScore: 8.3AV:A/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.89% Percentile: 76%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 9.04 | 9.10 | 10.04 | 10.10

  • debiandebian_linux

    5.0

  • fedoraprojectfedora

    13

  • linuxlinux_kernel

    < 2.6.36

References (14)