Description
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Published: 2014-03-11
Score: 7.8 High
EPSS: 3.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-2906-1 linux-2.6 security update
EUVD EUVD EUVD-2014-0181 The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Ubuntu USN Ubuntu USN USN-2173-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-2174-1 Linux kernel (EC2) vulnerabilities
Ubuntu USN Ubuntu USN USN-2221-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-2223-1 Linux kernel (Quantal HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2224-1 Linux kernel (Raring HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2225-1 Linux kernel (Saucy HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2227-1 Linux kernel (OMAP4) vulnerabilities
Ubuntu USN Ubuntu USN USN-2228-1 Linux kernel vulnerabilities
History

No history.

Subscriptions

Canonical Ubuntu Linux
F5 Big-ip Access Policy Manager Big-ip Advanced Firewall Manager Big-ip Analytics Big-ip Application Acceleration Manager Big-ip Application Security Manager Big-ip Edge Gateway Big-ip Enterprise Manager Big-ip Global Traffic Manager Big-ip Link Controller Big-ip Local Traffic Manager Big-ip Policy Enforcement Manager Big-ip Protocol Security Module Big-ip Wan Optimization Manager Big-ip Webaccelerator Big-iq Adc Big-iq Centralized Management Big-iq Cloud Big-iq Device Big-iq Security
Linux Linux Kernel
Redhat Enterprise Linux Enterprise Linux Desktop Enterprise Linux Eus Enterprise Linux Server Enterprise Linux Server Aus Enterprise Linux Server Tus Enterprise Linux Workstation Rhel Eus Rhel Mission Critical
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T09:05:38.283Z

Reserved: 2013-12-03T00:00:00.000Z

Link: CVE-2014-0101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-03-11T13:01:06.733

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-0101

cve-icon Redhat

Severity : Important

Publid Date: 2014-03-03T00:00:00Z

Links: CVE-2014-0101 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses