CVE-2014-3687

Advisory lineage Upstream: 0 Downstream: 13
Modified
Published: 10 Nov 2014, 11:00
Last modified:06 Aug 2024, 10:50

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
3.38% LOW
3% probability +1.40%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Nov 2014, 11:00
Published
Vulnerability first disclosed
06 Aug 2024, 10:50
Last Modified
Vulnerability information updated

Description

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 3.38% Percentile: 88%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    12.04

  • debiandebian_linux

    7.0

  • linuxlinux_kernel

    ≥ 2.6.27, < 3.2.64 | ≥ 3.3, < 3.4.107 | ≥ 3.5, < 3.10.61 | ≥ 3.11, < 3.12.34 | ≥ 3.13, < 3.14.25 | ≥ 3.15, < 3.16.35 | ≥ 3.17, < 3.17.4

  • novellsuse_linux_enterprise_desktop

    12.0

  • novellsuse_linux_enterprise_server

    12.0

  • opensuseevergreen

    11.4

  • oraclelinux

    5 | 6 | 7

  • redhatenterprise_mrg

    2.0

  • suselinux_enterprise_real_time_extension

    11:sp3

  • suselinux_enterprise_software_development_kit

    12

  • suselinux_enterprise_workstation_extension

    12

  • susesuse_linux_enterprise_server

    11:sp2

References (22)