VDB
CVE-2008-3526
CVE-2008-3526
PUBLISHED
Reported by redhat · Published August 27, 2008
Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Aug 27, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 32190 third-party-advisoryx_refsource_SECUNIA
- 32393 third-party-advisoryx_refsource_SECUNIA
- DSA-1636 vendor-advisoryx_refsource_DEBIAN
- 31881 third-party-advisoryx_refsource_SECUNIA
- MDVSA-2008:223 vendor-advisoryx_refsource_MANDRIVA
- USN-659-1 vendor-advisoryx_refsource_UBUNTU
- SUSE-SA:2008:053 vendor-advisoryx_refsource_SUSE
- RHSA-2008:0857 vendor-advisoryx_refsource_REDHAT
- [oss-security] 20080826 CVE-2008-3526 Linux kernel sctp_setsockopt_auth_key() integer overflow mailing-listx_refsource_MLIST
- x_refsource_CONFIRM
- linux-kernel-sctpsetsockoptauthkey-dos(44723) vdb-entryx_refsource_XF
- 30847 vdb-entryx_refsource_BID