CVE-2013-4350

Description

The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.323

Associated Vulnerability

VulnerabilityOS Platform
Linux hardware enablement kernel from Raring (USN-2041-1) linux-image-3.8.0-34-generic_3.8.0-34.49~precise1_i386.debLinux
Linux hardware enablement kernel from Raring (USN-2041-1) linux-image-3.8.0-34-generic_3.8.0-34.49~precise1_amd64.debLinux
Dtrace-modules-3.8.13-26.el6uek update (ELSA-2014-3002) dtrace-modules-3.8.13-26.el6uek-0.4.2-3.el6.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234