vendor:
Kernel
by:
Jon Oberheide
7,8
CVSS
HIGH
DoS
399
CWE
Product Name: Kernel
Affected Version From: 2.6.33.3
Affected Version To: 2.6.33.3
Patch Exists: YES
Related CWE: CVE-2010-1173
CPE: 2.6.33.3
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0631/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2010-1173/, https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0003-cve-2010-1173/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-1173/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0504/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
Linux Kernel <= 2.6.33.3 SCTP INIT Remote DoS
The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.
Mitigation:
Upgrade to the latest version of Linux Kernel