2 results (0.010 seconds)

CVSS: 7.5EPSS: 7%CPEs: 4EXPL: 0

Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer." • http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7c3ceb4fb9667f34f1599a062efecf4cdc4a4ce5 http://secunia.com/advisories/20716 http://secunia.com/advisories/21465 http://secunia.com/advisories/22417 http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm http://www.redhat.com/support/errata/RHSA-2006-0575.html http://www.securityfocus.com/bid/17955 http://www.trustix.org/errata/2006/0026 http://www.ubuntu.com/usn/usn-302-1 https:/&#x • CWE-667: Improper Locking •

CVSS: 7.8EPSS: 21%CPEs: 1EXPL: 0

Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks. • http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0227.html http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=62b08083ec3dbfd7e533c8d230dd1d8191a6e813 http://labs.musecurity.com/advisories/MU-200605-01.txt http://secunia.com/advisories/19990 http://secunia.com/advisories/20157 http://secunia.com/advisories/20237 http://secunia.com/advisories/20398 http://secunia.com/advisories/20671 http://secunia.com/advisories/20716 http://secunia.com/ •