cbcvebase.
CVE-2014-3673
published 2014-11-10

CVE-2014-3673: The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 3.16.7-1 (bookworm)linux 3.16.7-1 (bookworm)
linuxlinux_kernel>= 0 < 3.16.7-13.16.7-1
linuxlinux_kernel>= 0 < 3.16.7-13.16.7-1
linuxlinux_kernel>= 0 < 3.16.7-13.16.7-1
linuxlinux_kernel>= 0 < 3.16.7-13.16.7-1
linuxlinux_kernel>= 0 < 3.13.0-43.723.13.0-43.72
linuxlinux_kernel>= 2.6.12 < 3.2.643.2.64
linuxlinux_kernel>= 3.11 < 3.12.343.12.34
linuxlinux_kernel>= 3.13 < 3.14.253.14.25
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.17.43.17.4
linuxlinux_kernel>= 3.3 < 3.4.1073.4.107
linuxlinux_kernel>= 3.5 < 3.10.613.10.61
opensuseevergreen
oraclelinux
oraclelinux
oraclelinux
redhatenterprise_linux
redhatenterprise_mrg
suselinux_enterprise_software_development_kit
suselinux_enterprise_workstation_extension
susesuse_linux_enterprise_server
susesuse_linux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH