|
|

CVE Reference: CVE-2008-4113 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-4113 |
|
|
Description: The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/45188 UBUNTU http://www.ubuntu.com/usn/usn-659-1 SUSE http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html ST 1021000 SREASON http://securityreason.com/securityalert/4266 SAID Secunia Advisory: SA32393 Secunia Advisory: SA32190 REDHAT http://www.redhat.com/support/errata/RHSA-2008-0857.html MLIST http://www.openwall.com/lists/oss-security/2008/09/26/6 MISC http://www.trapkit.de/advisories/TKADV2008-007.txt MILW0RM http://www.milw0rm.com/exploits/7618 DEBIAN http://www.debian.org/security/2008/dsa-1655 CONFIRM http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.4 http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=d97240552cd98c4b07322f30f66fd9c3ba4171de BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/496256/100/0/threaded BID 31121 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |