Title: Linux Kernel Netfilter xt_sctp 0 Chunk Length Infinite Loop DoS
Info
Disclosure
Jun 19, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Kernel contains a flaw that may allow a remote denial of service. The issue is triggered when a user sends data with a 0 chunk length value that the 'xt_sctp' code fails to check, resulting in loss of availability for the platform.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 2.6.17.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.