7.8
CVSSv2

CVE-2013-5209

Published: 29/08/2013 Updated: 18/03/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 up to and including 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote malicious users to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.2

freebsd freebsd 8.3

freebsd freebsd 9.0

freebsd freebsd 9.1

Vendor Advisories

Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a privilege escalation or information leak The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-3077 Clement Lecigne from the Google Security Team reported an integer overflow in computing the size of a temporary buf ...
Debian Bug report logs - #720468 kfreebsd-9: CVE-2013-3077: local ip_multicast buffer overflow Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 11:45:02 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/ ...
Debian Bug report logs - #754237 kfreebsd-9: SCTP kernel memory disclosures (CVE-2014-3953) Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 8 Jul 2014 22:51:01 UTC Severity: grave Tags: security, upstream, wheezy Found in versions kfreeb ...
Debian Bug report logs - #720475 kfreebsd-9: CVE-2013-5209: sctp kernel memory disclosure Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 12:03:06 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/90-1 ...