Vulnerability CVE-2013-4350


Published: 2013-09-25   Modified: 2013-09-27

Description:
The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network.

See advisories in our WLB2 database:
Topic
Author
Date
High
Linux kernel 3.6.32/2.6.18 net/sctp ipv6 ipsec encryption bug
Alan Chester
13.09.2013

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Linux -> Linux kernel 

 References:
https://github.com/torvalds/linux/commit/95ee62083cb6453e056562d91f597552021e6ae7
http://www.openwall.com/lists/oss-security/2013/09/13/3
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=95ee62083cb6453e056562d91f597552021e6ae7
https://bugzilla.redhat.com/show_bug.cgi?id=1007872
http://www.ubuntu.com/usn/USN-2049-1
http://www.ubuntu.com/usn/USN-2045-1
http://www.ubuntu.com/usn/USN-2041-1

Copyright 2026, cxsecurity.com

 

Back to Top