oss-sec mailing list archives

Re: CVE for FreeBSD SCTP remote DoS?


From: "Simon L. B. Nielsen" <simon () FreeBSD org>
Date: Tue, 28 Aug 2012 09:50:41 +0100

On Tue, Aug 28, 2012 at 7:25 AM, Raphael Geissert <geissert () debian org> wrote:
Hi everyone,

There appears to be a remote DoS (via a NULL pointer dereference in the
kernel) vulnerability in FreeBSD's SCTP implementation[1].

Has a CVE id been assigned to it already?

[1]http://www.exploit-db.com/exploits/20226/

I don't think have one gotten assigned, but probably should. Probably
best to go to Mitre to make sure we don't accidentally get a
duplicate. Feel free to requeste one, or I can do it later. Please cc:
secteam () freebsd org on any request to minimize risk of confusion.

-- 
Simon L. B. Nielsen
Hat: FreeBSD Security Officer


Current thread: