CVE-2014-8613
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://www.freebsd.org/security/advisories/FreeBSD-SA-15:03.sctp.asc
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| freebsd | 8.4 | affected | |
| freebsd | 9.3 | affected | |
| freebsd | 10.1 | affected | |
References
Verify integrity in audit chain (admin only). AS-IS.