CVE-2014-4667

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 03 Jul 2014, 01:00
Last modified:06 Aug 2024, 11:27

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
14.14% MEDIUM
14% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2014, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 11:27
Last Modified
Vulnerability information updated

Description

The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 14.14% Percentile: 94%

Affected Systems

  • canonicalubuntu_linux

    12.04

  • debiandebian_linux

    7.0

  • linuxlinux_kernel

    < 3.15.2

  • suselinux_enterprise_desktop

    11:sp3

  • suselinux_enterprise_real_time_extension

    11:sp3

  • suselinux_enterprise_server

    10:sp4 | 11:sp3

References (18)