PT-2020-2071 · Usrsctp+7 · Usrsctp+7

Natalie Silvanovich

·

Published

2020-03-06

·

Updated

2024-12-12

·

CVE-2019-20503

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions usrsctp versions prior to 2019-12-20
Description The issue is related to out-of-bounds reads in the sctp load addresses from init function of the usrsctp implementation. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For usrsctp versions prior to 2019-12-20, update to a version released after 2019-12-20 to resolve the issue. As a temporary workaround, consider restricting access to the sctp load addresses from init function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1461
ALT-PU-2020-1485
ALT-PU-2020-1486
ALT-PU-2020-1493
ALT-PU-2020-1515
AZL-35345
AZL-9920
BDU:2020-01910
CESA-2020_0815
CESA-2020_0816
CESA-2020_0820
CESA-2020_0905
CESA-2020_0914
CESA-2020_0919
CVE-2019-20503
DLA-2140-1
DLA-2150-1
DLA-3481-1
DSA-4639-1
DSA-4642-1
DSA-4645-1
MGASA-2020-0141
MGASA-2020-0142
MGASA-2020-0149
OPENSUSE-SU-2020:0340-1
OPENSUSE-SU-2020:0365-1
OPENSUSE-SU-2020:0366-1
OPENSUSE-SU-2020:0389-1
OPENSUSE-SU-2020_0340-1
OPENSUSE-SU-2020_0365-1
OPENSUSE-SU-2020_0366-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0815
RHSA-2020:0816
RHSA-2020:0819
RHSA-2020:0820
RHSA-2020:0905
RHSA-2020:0914
RHSA-2020:0918
RHSA-2020:0919
RHSA-2020:1270
RHSA-2020_0815
RHSA-2020_0816
RHSA-2020_0820
RHSA-2020_0905
RHSA-2020_0914
RHSA-2020_0919
RHSA-2020_1270
SUSE-SU-2020:0686-1
SUSE-SU-2020:0717-1
SUSE-SU-2020:0721-1
SUSE-SU-2020:14312-1
SUSE-SU-2020_0686-1
SUSE-SU-2020_0717-1
SUSE-SU-2020_14312-1
USN-4299-1
USN-4328-1
USN-4335-1

Affected Products

Alt Linux
Astra Linux
Centos
Google Chrome
Red Hat
Suse
Ubuntu
Usrsctp