English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

FreeBSD SCTP ASCONF Chunk Processing Denial of Service Vulnerability


Secunia ID

SA50189

CVE-ID

CVE-2012-3549

Release Date

10 Aug 2012

Last Change

25 Oct 2012

Criticality

Moderately Critical

Solution Status

Unpatched

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

IOActive has discovered a vulnerability in FreeBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a NULL pointer dereference error when handling ASCONF chunks and can be exploited to cause a kernel panic via a specially crafted verification tag sent in a SCTP packet.

The vulnerability is confirmed in version 8.1. Other versions may also be affected.

Solution

No official solution is currently available.

Reported by

Shaun Colley, IOActive.

Original Advisory

http://www.exploit-db.com/exploits/20226/