CVE-2010-3705

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 26 Nov 2010, 19:00
Last modified:07 Aug 2024, 03:18

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.3 HIGH
v2.0 (nvd)
EPSS Score
2.02% LOW
2% probability +0.81%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Nov 2010, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 03:18
Last Modified
Vulnerability information updated

Description

The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.

CVSS Metrics

  • v2.0HIGHScore: 8.3AV:A/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 2.02% Percentile: 79%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 9.04 | 9.10 | 10.04 | 10.10

  • debiandebian_linux

    5.0

  • fedoraprojectfedora

    13

  • linuxlinux kernel

    < 2.6.36

References (14)