CVE-2015-5283 - CERT CVE
ID CVE-2015-5283
Sažetak The sctp_init function in net/sctp/protocol.c in the Linux kernel before 4.2.3 has an incorrect sequence of protocol-initialization steps, which allows local users to cause a denial of service (panic or memory corruption) by creating SCTP sockets before all of the steps have finished.
Reference
CVSS
Base: 4.7
Impact: 6.9
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE COMPLETE
CVSS vektor AV:L/AC:M/Au:N/C:N/I:N/A:C
Zadnje važnije ažuriranje 13-02-2023 - 00:52
Objavljeno 19-10-2015 - 10:59