7.5
CVSSv3

CVE-2014-3687

Published: 10/11/2014 Updated: 13/02/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel up to and including 3.17.2 allows remote malicious users to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

redhat enterprise mrg 2.0

canonical ubuntu linux 12.04

opensuse evergreen 11.4

novell suse linux enterprise server 12.0

suse linux enterprise real time extension 11

debian debian linux 7.0

novell suse linux enterprise desktop 12.0

suse linux enterprise workstation extension 12

suse linux enterprise software development kit 12

suse suse linux enterprise server 11

oracle linux 5

oracle linux 6

oracle linux 7

Vendor Advisories

Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues, several bugs,and add one enhancement are now available for Red Hat Enterprise Linux 65Extended Update SupportRed Hat Product Secu ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix three security issues and several bugs arenow available for Red Hat Enterprise Linux 64 Extended Update SupportRed Hat Product Security has rated this update as having I ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix three security issues are now availablefor Red Hat Enterprise Linux 62 Advanced Update SupportRed Hat Product Security has rated this update as having Important securityimpact Comm ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues and several bugsare now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Important securityimpact ...
A flaw was found in the way the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation handled duplicate Address Configuration Change Chunks (ASCONF) A remote attacker could use either of these flaws to crash the system ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN-2448-1 introduced a regression in the Linux kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
USN-2447-1 introduced a regression in the Linux kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...