Novell Home

CVE-2008-4576

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-4576 at MITRE

Description

sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.

NVD CVSS v2 Base Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Novell/SUSE information

Novell Bugzilla entry: 433757

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • kernel-bigsmp >= 2.6.22.19-0.1
  • kernel-debug >= 2.6.22.19-0.1
  • kernel-default >= 2.6.22.19-0.1
  • kernel-kdump >= 2.6.22.19-0.1
  • kernel-ppc64 >= 2.6.22.19-0.1
  • kernel-source >= 2.6.22.19-0.1
  • kernel-syms >= 2.6.22.19-0.1
  • kernel-xen >= 2.6.22.19-0.1
  • kernel-xenpae >= 2.6.22.19-0.1
openSUSE 10.2
  • kernel-bigsmp >= 2.6.18.8-0.13
  • kernel-default >= 2.6.18.8-0.13
  • kernel-iseries64 >= 2.6.18.8-0.13
  • kernel-kdump >= 2.6.18.8-0.13
  • kernel-ppc64 >= 2.6.18.8-0.13
  • kernel-source >= 2.6.18.8-0.13
  • kernel-syms >= 2.6.18.8-0.13
  • kernel-xen >= 2.6.18.8-0.13
  • kernel-xenpae >= 2.6.18.8-0.13

© 2012 Novell