Vulnerability Description
The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states that trigger a NULL pointer dereference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.0 |
References
- http://marc.info/?l=linux-kernel&m=118128610219959&w=2
- http://marc.info/?l=linux-kernel&m=118128622431272&w=2
- http://osvdb.org/37112
- http://rhn.redhat.com/errata/RHSA-2007-0488.html
- http://secunia.com/advisories/25838
- http://secunia.com/advisories/25961
- http://secunia.com/advisories/26133
- http://secunia.com/advisories/26139
- http://secunia.com/advisories/26289
- http://secunia.com/advisories/26450
- http://secunia.com/advisories/26620
- http://secunia.com/advisories/26664
- http://secunia.com/advisories/26760
- http://secunia.com/advisories/27227
- http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm
FAQ
What is CVE-2007-2876?
CVE-2007-2876 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cau...
How severe is CVE-2007-2876?
CVE-2007-2876 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2876?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.