7.8
CVSSv2

CVE-2014-8613

Published: 02/02/2015 Updated: 04/02/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote malicious users to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.3

freebsd freebsd 8.4

freebsd freebsd 10.1

Vendor Advisories

Debian Bug report logs - #776415 kfreebsd-10: CVE-2014-8612: SCTP kernel mem disclosure/corruption Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 27 Jan 2015 20:21:01 UTC Severity: grave Tags: ...
Debian Bug report logs - #776416 kfreebsd-10: CVE-2014-8613: SCTP stream reset vulnerability Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 27 Jan 2015 20:24:01 UTC Severity: grave Tags: patch, ...