FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a (1) SCTP_SNDRCV, (2) SCTP_EXTRCV, or (3) SCTP_RCVINFO SCTP cmsg or a (4) SCTP_PEER_ADDR_CHANGE, (5) SCTP_REMOTE_ERROR, or (6) SCTP_AUTHENTICATION_EVENT notification.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-07-15T14:00:00
Updated: 2024-08-06T10:57:17.979Z
Reserved: 2014-06-03T00:00:00
Link: CVE-2014-3953
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-07-15T14:55:09.840
Modified: 2024-11-21T02:09:12.623
Link: CVE-2014-3953
Redhat
No data.