CVE-2008-4576 : Detail

CVE-2008-4576

Authorization problems
A07-Identif. and Authent. Fail
3.61%V4
Network
2008-10-15
17h00 +00:00
2017-09-28
10h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE Other No informations.

Metrics

Metrics Score Severity CVSS Vector Source
V2 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Linux>>Linux_kernel >> Version To (including) 2.6.25.17

Linux>>Linux_kernel >> Version 2.2.27

Linux>>Linux_kernel >> Version 2.4.36

Linux>>Linux_kernel >> Version 2.4.36.1

Linux>>Linux_kernel >> Version 2.4.36.2

Linux>>Linux_kernel >> Version 2.4.36.3

Linux>>Linux_kernel >> Version 2.4.36.4

Linux>>Linux_kernel >> Version 2.4.36.5

Linux>>Linux_kernel >> Version 2.4.36.6

Linux>>Linux_kernel >> Version 2.6

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.18

Linux>>Linux_kernel >> Version 2.6.19.4

Linux>>Linux_kernel >> Version 2.6.19.5

Linux>>Linux_kernel >> Version 2.6.19.6

Linux>>Linux_kernel >> Version 2.6.19.7

Linux>>Linux_kernel >> Version 2.6.20.16

Linux>>Linux_kernel >> Version 2.6.20.17

Linux>>Linux_kernel >> Version 2.6.20.18

Linux>>Linux_kernel >> Version 2.6.20.19

Linux>>Linux_kernel >> Version 2.6.20.20

Linux>>Linux_kernel >> Version 2.6.20.21

Linux>>Linux_kernel >> Version 2.6.21.5

Linux>>Linux_kernel >> Version 2.6.21.6

Linux>>Linux_kernel >> Version 2.6.21.7

Linux>>Linux_kernel >> Version 2.6.22

Linux>>Linux_kernel >> Version 2.6.22.1

Linux>>Linux_kernel >> Version 2.6.22.2

Linux>>Linux_kernel >> Version 2.6.22.8

Linux>>Linux_kernel >> Version 2.6.22.9

Linux>>Linux_kernel >> Version 2.6.22.10

Linux>>Linux_kernel >> Version 2.6.22.11

Linux>>Linux_kernel >> Version 2.6.22.12

Linux>>Linux_kernel >> Version 2.6.22.13

Linux>>Linux_kernel >> Version 2.6.22.14

Linux>>Linux_kernel >> Version 2.6.22.15

Linux>>Linux_kernel >> Version 2.6.22.17

Linux>>Linux_kernel >> Version 2.6.22.18

Linux>>Linux_kernel >> Version 2.6.22.19

Linux>>Linux_kernel >> Version 2.6.22.20

Linux>>Linux_kernel >> Version 2.6.22.21

Linux>>Linux_kernel >> Version 2.6.22.22

Linux>>Linux_kernel >> Version 2.6.22_rc1

    Linux>>Linux_kernel >> Version 2.6.22_rc7

      Linux>>Linux_kernel >> Version 2.6.23

      Linux>>Linux_kernel >> Version 2.6.23.8

      Linux>>Linux_kernel >> Version 2.6.23.9

      Linux>>Linux_kernel >> Version 2.6.23.10

      Linux>>Linux_kernel >> Version 2.6.23.11

      Linux>>Linux_kernel >> Version 2.6.23.12

      Linux>>Linux_kernel >> Version 2.6.23.13

      Linux>>Linux_kernel >> Version 2.6.23.15

      Linux>>Linux_kernel >> Version 2.6.23.16

      Linux>>Linux_kernel >> Version 2.6.23.17

      Linux>>Linux_kernel >> Version 2.6.23_rc1

        Linux>>Linux_kernel >> Version 2.6.24

        Linux>>Linux_kernel >> Version 2.6.24.1

        Linux>>Linux_kernel >> Version 2.6.24.2

        Linux>>Linux_kernel >> Version 2.6.24.3

        Linux>>Linux_kernel >> Version 2.6.24.4

        Linux>>Linux_kernel >> Version 2.6.24.5

        Linux>>Linux_kernel >> Version 2.6.24.6

        Linux>>Linux_kernel >> Version 2.6.24.7

        Linux>>Linux_kernel >> Version 2.6.24_rc1

          Linux>>Linux_kernel >> Version 2.6.24_rc4

            Linux>>Linux_kernel >> Version 2.6.24_rc5

              Linux>>Linux_kernel >> Version 2.6.25

              Linux>>Linux_kernel >> Version 2.6.25.1

              Linux>>Linux_kernel >> Version 2.6.25.1

                Linux>>Linux_kernel >> Version 2.6.25.2

                Linux>>Linux_kernel >> Version 2.6.25.2

                  Linux>>Linux_kernel >> Version 2.6.25.3

                  Linux>>Linux_kernel >> Version 2.6.25.3

                    Linux>>Linux_kernel >> Version 2.6.25.4

                    Linux>>Linux_kernel >> Version 2.6.25.4

                      Linux>>Linux_kernel >> Version 2.6.25.5

                      Linux>>Linux_kernel >> Version 2.6.25.5

                        Linux>>Linux_kernel >> Version 2.6.25.6

                        Linux>>Linux_kernel >> Version 2.6.25.6

                          Linux>>Linux_kernel >> Version 2.6.25.7

                          Linux>>Linux_kernel >> Version 2.6.25.7

                            Linux>>Linux_kernel >> Version 2.6.25.8

                            Linux>>Linux_kernel >> Version 2.6.25.8

                              Linux>>Linux_kernel >> Version 2.6.25.9

                              Linux>>Linux_kernel >> Version 2.6.25.9

                                Linux>>Linux_kernel >> Version 2.6.25.10

                                Linux>>Linux_kernel >> Version 2.6.25.10

                                  Linux>>Linux_kernel >> Version 2.6.25.11

                                  Linux>>Linux_kernel >> Version 2.6.25.11

                                    Linux>>Linux_kernel >> Version 2.6.25.12

                                    Linux>>Linux_kernel >> Version 2.6.25.12

                                      Linux>>Linux_kernel >> Version 2.6.25.13

                                      Linux>>Linux_kernel >> Version 2.6.25.14

                                      Linux>>Linux_kernel >> Version 2.6.25.15

                                      Linux>>Linux_kernel >> Version 2.6.25.16

                                      References

                                      http://secunia.com/advisories/32998
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://www.redhat.com/support/errata/RHSA-2009-0009.html
                                      Tags : vendor-advisory, x_refsource_REDHAT
                                      http://www.securityfocus.com/bid/31634
                                      Tags : vdb-entry, x_refsource_BID
                                      http://secunia.com/advisories/33586
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://www.debian.org/security/2008/dsa-1687
                                      Tags : vendor-advisory, x_refsource_DEBIAN
                                      http://secunia.com/advisories/32918
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://www.ubuntu.com/usn/usn-679-1
                                      Tags : vendor-advisory, x_refsource_UBUNTU
                                      http://secunia.com/advisories/32759
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://secunia.com/advisories/33180
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://secunia.com/advisories/32370
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://www.redhat.com/support/errata/RHSA-2008-1017.html
                                      Tags : vendor-advisory, x_refsource_REDHAT
                                      http://secunia.com/advisories/32386
                                      Tags : third-party-advisory, x_refsource_SECUNIA
                                      http://www.debian.org/security/2008/dsa-1681
                                      Tags : vendor-advisory, x_refsource_DEBIAN
                                      http://secunia.com/advisories/33182
                                      Tags : third-party-advisory, x_refsource_SECUNIA