oss-sec mailing list archives

CVE request: FreeBSD SCTP remote DoS


From: Raphael Geissert <geissert () debian org>
Date: Tue, 28 Aug 2012 14:39:22 -0500

On Tuesday 28 August 2012 03:50:41 Simon L. B. Nielsen wrote:
On Tue, Aug 28, 2012 at 7:25 AM, Raphael Geissert <geissert () debian org> 
wrote:
There appears to be a remote DoS (via a NULL pointer dereference in the
kernel) vulnerability in FreeBSD's SCTP implementation[1].

Has a CVE id been assigned to it already?

[1]http://www.exploit-db.com/exploits/20226/

I don't think have one gotten assigned, but probably should. Probably
best to go to Mitre to make sure we don't accidentally get a
duplicate. Feel free to requeste one, or I can do it later. Please cc:
secteam () freebsd org on any request to minimize risk of confusion.

Kurt, could you please assign one?

Thanks in advance.

Kind regards,
-- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net


Current thread: