7.5
CVSSv3

CVE-2014-3673

Published: 10/11/2014 Updated: 13/02/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The SCTP implementation in the Linux kernel up to and including 3.17.2 allows remote malicious users to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

redhat enterprise linux 5.0

redhat enterprise mrg 2.0

canonical ubuntu linux 12.04

debian debian linux 7.0

opensuse evergreen 11.4

suse linux enterprise workstation extension 12

suse suse linux enterprise server 12

suse linux enterprise software development kit 12

suse suse linux enterprise server 11

suse suse linux enterprise server 10

oracle linux 5

oracle linux 6

oracle linux 7

Vendor Advisories

Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues, several bugs,and add one enhancement are now available for Red Hat Enterprise Linux 65Extended Update SupportRed Hat Product Secu ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix three security issues and several bugs arenow available for Red Hat Enterprise Linux 64 Extended Update SupportRed Hat Product Security has rated this update as having I ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix three security issues are now availablefor Red Hat Enterprise Linux 62 Advanced Update SupportRed Hat Product Security has rated this update as having Important securityimpact Comm ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues and several bugsare now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Important securityimpact ...
A flaw was found in the way the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation handled malformed Address Configuration Change Chunks (ASCONF) A remote attacker could use either of these flaws to crash the system ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN-2448-1 introduced a regression in the Linux kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN-2447-1 introduced a regression in the Linux kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...