CVE-2014-4667

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 03 Jul 2014, 01:00
Last modified:06 Aug 2024, 11:27

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
5.93% LOW
6% probability -8.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2014, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 11:27
Last Modified
Vulnerability information updated

Description

The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 5.93% Percentile: 92%

Affected Systems

  • canonicalubuntu_linux

    12.04

  • debiandebian_linux

    7.0

  • linuxlinux kernel

    < 3.15.2

  • suselinux_enterprise_desktop

    11:sp3

  • suselinux_enterprise_real_time_extension

    11:sp3

  • suselinux_enterprise_server

    10:sp4 | 11:sp3

References (18)