CVE-2008-4445 PUBLISHED CVSS 4.699999809265137 MEDIUM

The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bounds established by SCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function, a different vulnerability than CVE-2008-4113.

EPSS 0.07% · 22.2th percentile

Risk Scores

CVSS v2.0
4.699999809265137
EPSS Score
0.07%
22.2th percentile

Affected Products

VendorProductVersions
n/an/an/a
linuxlinux_kernel0, 2.2.27, 2.4.36

Timeline

References

Open in Interactive Console →