PT-2013-3596 · Linux+3 · Linux Kernel+3

Karl Heiss

·

Published

2013-06-21

·

Updated

2023-02-13

·

CVE-2013-2206

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.8.5
Description The issue is related to the SCTP implementation in the Linux kernel, specifically the sctp sf do 5 2 4 dupcook function. It does not properly handle associations when processing a duplicate COOKIE ECHO chunk, allowing remote attackers to cause a denial of service, potentially leading to a system crash, via crafted SCTP traffic.
Recommendations For Linux kernel versions prior to 3.8.5, update to version 3.8.5 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CESA-2013_1173
CVE-2013-2206
DSA-2766-1
RHSA-2013:1166
RHSA-2013:1173
RHSA-2013:1195
RHSA-2013_1166
RHSA-2013_1173
SUSE-RU-2015:0621-1
SUSE-SU-2013_1744-1
SUSE-SU-2013_1748-1
SUSE-SU-2013_1749-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1809-1
USN-1811-1
USN-1812-1
USN-1813-1
USN-1814-1
USN-1939-1
USN-1940-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse