PT-2008-6870 · Linux Foundation+1 · Linux+1

Publicado

1970-01-01

·

Atualizado

2017-09-29

·

CVE-2008-4576

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions linux-headers-2.6.18-6 versions 2.6.18-6 and earlier linux-image-2.6.18-6 versions 2.6.18-6 and earlier linux-modules-2.6.18-6 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-686-bigmem versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-generic versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-legacy versions 2.6.18-6 and earlier linux-headers-2.6.18-6-alpha-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-footbridge versions 2.6.18-6 and earlier linux-headers-2.6.18-6-iop32x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-itanium versions 2.6.18-6 and earlier linux-headers-2.6.18-6-k7 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-mckinley versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-parisc64-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc-miboot versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-powerpc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-qemu versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r3k-kn02 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r4k-ip22 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r4k-kn04 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r5k-cobalt versions 2.6.18-6 and earlier linux-headers-2.6.18-6-r5k-ip32 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-s390 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-s390x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-s3c2410 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sb1-bcm91250a versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sb1a-bcm91480b versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc32 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-sparc64-smp versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-alpha versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-k7 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-powerpc versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-powerpc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-s390x versions 2.6.18-6 and earlier linux-headers-2.6.18-6-vserver-sparc64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-amd64 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver-686 versions 2.6.18-6 and earlier linux-headers-2.6.18-6-xen-vserver-amd64 versions 2.6.18-6 and earlier linux-image-2.6.18-6 versions 2.6.18-6 and earlier linux-image-2.6.18-6-686 versions 2.6.18-6 and earlier linux-image-2.6.18-6-686-bigmem versions 2.6.18-6 and earlier linux-image-2.6.18-6-alpha versions 2.6.18-6 and earlier linux-image-2.6.18-6-alpha-generic versions 2.6.18-6 and earlier linux-image-2.6.18-6-alpha-legacy versions 2.6.18-6 and earlier linux-image-2.6.18-6-alpha-smp versions 2.6.18-6 and earlier linux-image-2.6.18-6-amd64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-footbridge versions 2.6.18-6 and earlier linux-image-2.6.18-6-iop32x versions 2.6.18-6 and earlier linux-image-2.6.18-6-itanium versions 2.6.18-6 and earlier linux-image-2.6.18-6-k7 versions 2.6.18-6 and earlier linux-image-2.6.18-6-mckinley versions 2.6.18-6 and earlier linux-image-2.6.18-6-parisc versions 2.6.18-6 and earlier linux-image-2.6.18-6-parisc64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-parisc64-smp versions 2.6.18-6 and earlier linux-image-2.6.18-6-powerpc versions 2.6.18-6 and earlier linux-image-2.6.18-6-powerpc-miboot versions 2.6.18-6 and earlier linux-image-2.6.18-6-powerpc-smp versions 2.6.18-6 and earlier linux-image-2.6.18-6-powerpc64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-qemu versions 2.6.18-6 and earlier linux-image-2.6.18-6-r3k-kn02 versions 2.6.18-6 and earlier linux-image-2.6.18-6-r4k-ip22 versions 2.6.18-6 and earlier linux-image-2.6.18-6-r4k-kn04 versions 2.6.18-6 and earlier linux-image-2.6.18-6-r5k-cobalt versions 2.6.18-6 and earlier linux-image-2.6.18-6-r5k-ip32 versions 2.6.18-6 and earlier linux-image-2.6.18-6-s390 versions 2.6.18-6 and earlier linux-image-2.6.18-6-s390x versions 2.6.18-6 and earlier linux-image-2.6.18-6-s3c2410 versions 2.6.18-6 and earlier linux-image-2.6.18-6-sb1-bcm91250a versions 2.6.18-6 and earlier linux-image-2.6.18-6-sb1a-bcm91480b versions 2.6.18-6 and earlier linux-image-2.6.18-6-sparc32 versions 2.6.18-6 and earlier linux-image-2.6.18-6-sparc64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-sparc64-smp versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-686 versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-alpha versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-amd64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-k7 versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-powerpc versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-powerpc64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-s390x versions 2.6.18-6 and earlier linux-image-2.6.18-6-vserver-sparc64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen-686 versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen-amd64 versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen-vserver versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen-vserver-686 versions 2.6.18-6 and earlier linux-image-2.6.18-6-xen-vserver-amd64 versions 2.6.18-6 and earlier kernel-rt versions prior to 2.6.25.18 kernel-rt debug versions prior to 2.6.25.18 fai-kernels versions 2.6.18-6 and earlier linux-doc-2.6.18 versions 2.6.18-6 and earlier linux-manual-2.6.18 versions 2.6.18-6 and earlier linux-patch-debian-2.6.18 versions 2.6.18-6 and earlier linux-source-2.6.18 versions 2.6.18-6 and earlier linux-support-2.6.18-6 versions 2.6.18-6 and earlier linux-tree-2.6.18 versions 2.6.18-6 and earlier
Description The issue is related to multiple vulnerabilities in the Linux kernel, specifically in the sctp module, which can be exploited remotely to cause a denial of service. The vulnerabilities can be triggered by an INIT-ACK packet that states the peer does not support AUTH, leading to the sctp process init function cleaning up active transports and causing an OOPS when the T1-Init timer expires.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00886
BDU:2015-01470
BDU:2015-01471
BDU:2015-01472
BDU:2015-01473
BDU:2015-01474
BDU:2015-01475
BDU:2015-01476
BDU:2015-01477
BDU:2015-01478
BDU:2015-01479
BDU:2015-01480
BDU:2015-01481
BDU:2015-01482
BDU:2015-01483
BDU:2015-01484
BDU:2015-01485
BDU:2015-01486
BDU:2015-01487
BDU:2015-01488
BDU:2015-01489
BDU:2015-01490
BDU:2015-01491
BDU:2015-01492
BDU:2015-01493
BDU:2015-01494
BDU:2015-01495
BDU:2015-01496
BDU:2015-01497
BDU:2015-01498
BDU:2015-01499
BDU:2015-01500
BDU:2015-01501
BDU:2015-01502
BDU:2015-01503
BDU:2015-01504
BDU:2015-01505
BDU:2015-01506
BDU:2015-01507
BDU:2015-01508
BDU:2015-01509
BDU:2015-01510
BDU:2015-01511
BDU:2015-01512
BDU:2015-01513
BDU:2015-01514
BDU:2015-01515
BDU:2015-01516
BDU:2015-01517
BDU:2015-01518
BDU:2015-01519
BDU:2015-01520
BDU:2015-01521
BDU:2015-01522
BDU:2015-01523
BDU:2015-01524
BDU:2015-01525
BDU:2015-01526
BDU:2015-01527
BDU:2015-01528
BDU:2015-01529
BDU:2015-01530
BDU:2015-01531
BDU:2015-01532
BDU:2015-01533
BDU:2015-01534
BDU:2015-01535
BDU:2015-01536
BDU:2015-01537
BDU:2015-01538
BDU:2015-01539
BDU:2015-01540
BDU:2015-01541
BDU:2015-01542
BDU:2015-01543
BDU:2015-01544
BDU:2015-01545
BDU:2015-01546
BDU:2015-01547
BDU:2015-01548
BDU:2015-01549
BDU:2015-01550
BDU:2015-01551
BDU:2015-01552
BDU:2015-01553
BDU:2015-01554
BDU:2015-01555
BDU:2015-01556
BDU:2015-01557
BDU:2015-01558
BDU:2015-01559
BDU:2015-01560
BDU:2015-01561
BDU:2015-01562
BDU:2015-01563
BDU:2015-01564
BDU:2015-01565
BDU:2015-01566
BDU:2015-01567
BDU:2015-01568
BDU:2015-01569
BDU:2015-01570
BDU:2015-01571
BDU:2015-01572
BDU:2015-01573
BDU:2015-01574
BDU:2015-01575
BDU:2015-01576
BDU:2015-01577
BDU:2015-01578
BDU:2015-01579
BDU:2015-01580
BDU:2015-01581
BDU:2015-01582
BDU:2015-01583
BDU:2015-01584
BDU:2015-01585
BDU:2015-01586
BDU:2015-01587
BDU:2015-01588
BDU:2015-01589
BDU:2015-01590
BDU:2015-01591
BDU:2015-01592
BDU:2015-01593
BDU:2015-01594
BDU:2015-05034
BDU:2015-05035
CVE-2008-4576
DSA-1681-1
DSA-1687-1
RHSA-2008:1017
RHSA-2008_1017
RHSA-2009:0009

Produtos afetados

Linux
Red Hat