CVE-2014-0101

UnknownEPSS 6.99%

Last modified

CVE-2014-0101 is a vulnerability of currently unknown severity. The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.. EPSS estimates a 6.99% chance of exploitation in the next 30 days.

Description

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.

Metrics

EPSS Probability
6.99%

93.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LinuxLinux Kernel>= 2.6.24, < 3.2.56
LinuxLinux Kernel>= 3.3, < 3.4.84
LinuxLinux Kernel>= 3.5, < 3.10.34
LinuxLinux Kernel>= 3.11, < 3.12.15
LinuxLinux Kernel>= 3.13, < 3.13.7
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.3
RedhatEnterprise Linux Eus6.4
RedhatEnterprise Linux Eus6.5
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.4
RedhatEnterprise Linux Server Aus6.5
RedhatEnterprise Linux Server Tus6.5
RedhatEnterprise Linux Workstation6.0
CanonicalUbuntu Linux10.04
F5Big-Ip Access Policy Manager>= 11.1.0, <= 11.5.3
F5Big-Ip Advanced Firewall Manager>= 11.3.0, <= 11.5.3
F5Big-Ip Analytics>= 11.1.0, <= 11.5.3
F5Big-Ip Application Acceleration Manager>= 11.4.0, <= 11.5.3
F5Big-Ip Application Security Manager>= 11.1.0, <= 11.5.3
F5Big-Ip Edge Gateway>= 11.1.0, <= 11.3.0
F5Big-Ip Enterprise Manager>= 2.1.0, <= 2.3.0
F5Big-Ip Enterprise Manager>= 3.0.0, <= 3.1.1
F5Big-Ip Global Traffic Manager>= 11.1.0, <= 11.5.3
F5Big-Ip Link Controller>= 11.1.0, <= 11.5.3
F5Big-Ip Local Traffic Manager>= 11.1.0, <= 11.5.3
F5Big-Ip Policy Enforcement Manager>= 11.3.0, <= 11.5.3
F5Big-Ip Protocol Security Module>= 11.1.0, <= 11.4.1
F5Big-Ip Wan Optimization Manager>= 11.1.0, <= 11.3.0
F5Big-Ip Webaccelerator>= 11.1.0, <= 11.3.0
F5Big-Iq Adc4.5.0
F5Big-Iq Centralized Management4.6.0
F5Big-Iq Cloud>= 4.0.0, <= 4.5.0
F5Big-Iq Device>= 4.2.0, <= 4.5.0
F5Big-Iq Security>= 4.0.0, <= 4.5.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-0101?
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
How severe is CVE-2014-0101?
Severity scoring for CVE-2014-0101 is pending analysis. The EPSS model estimates a 6.99% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0101?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-0101?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST