CVE-2014-5077
Last modified
CVE-2014-5077 is a vulnerability of currently unknown severity. The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association between two endpoints immediately after an exchange of INIT and INIT ACK chunks to establish an earlier association between these endpoints in the opposite direction.. EPSS estimates a 5.79% chance of exploitation in the next 30 days.
Description
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association between two endpoints immediately after an exchange of INIT and INIT ACK chunks to establish an earlier association between these endpoints in the opposite direction.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 2.6.24, < 3.2.63 | — |
| Linux | Linux Kernel | >= 3.3, < 3.4.103 | — |
| Linux | Linux Kernel | >= 3.5, < 3.10.53 | — |
| Linux | Linux Kernel | >= 3.11, < 3.12.27 | — |
| Linux | Linux Kernel | >= 3.13, < 3.14.17 | — |
| Linux | Linux Kernel | >= 3.15, < 3.15.10 | — |
| Suse | Linux Enterprise Desktop | 11 | Sp3 |
| Suse | Linux Enterprise Real Time Extension | 11 | Sp3 |
| Suse | Linux Enterprise Server | 11 | Sp3 |
| Redhat | Enterprise Linux Eus | 6.5 | — |
| Redhat | Enterprise Linux Server Aus | 6.2 | — |
| Redhat | Enterprise Linux Server Aus | 6.5 | — |
| Redhat | Enterprise Linux Server Tus | 6.5 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1083.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1668.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1763.htmlThird Party Advisory
- http://secunia.com/advisories/59777Third Party Advisory
- http://secunia.com/advisories/60430Third Party Advisory
- http://secunia.com/advisories/60545Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://secunia.com/advisories/60744Third Party Advisory
- http://secunia.com/advisories/62563Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/26/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68881Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030681Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2335-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2358-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2359-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1122982Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95134Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/1be9a950c646c9092fb3618197f7b6bfb50e82aaPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1083.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1668.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1763.htmlThird Party Advisory
- http://secunia.com/advisories/59777Third Party Advisory
- http://secunia.com/advisories/60430Third Party Advisory
- http://secunia.com/advisories/60545Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://secunia.com/advisories/60744Third Party Advisory
- http://secunia.com/advisories/62563Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/26/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68881Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030681Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2335-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2358-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2359-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1122982Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95134Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/1be9a950c646c9092fb3618197f7b6bfb50e82aaPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5077?
How severe is CVE-2014-5077?
How do I fix CVE-2014-5077?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-5071SQL injection vulnerability in the checkPassword function in…9.8
- CVE-2014-5072Cross-site request forgery (CSRF) vulnerability in WP Securi…
- CVE-2014-5073vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build …
- CVE-2014-5074Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6…
- CVE-2014-5075The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x…
- CVE-2014-5076The La Banque Postale application before 3.2.6 for Android d…
- CVE-2014-5081sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphide…9.8
- CVE-2014-5082Multiple SQL injection vulnerabilities in admin/admin.php in…
- CVE-2014-5083A Command Execution vulnerability exists in Sphider before 1…8.8
- CVE-2014-5084A Command Execution vulnerability exists in Sphider Pro 3.2 …8.8
- CVE-2014-5085A Command Execution vulnerability exists in Sphider Plus 3.2…8.8
- CVE-2014-5086A Command Execution vulnerability exists in Sphider Pro, and…8.8
Are you affected by CVE-2014-5077?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
