Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreeBSD 信息泄露漏洞
Vulnerability Description
FreeBSD是由Core Team团队负责的FreeBSD项目中的一套类Unix自由操作系统,是经过BSD、386BSD和4.4BSD发展而来的类Unix的一个重要分支。 FreeBSD 8.3至9.2-PRERELEASE版本中的内核中的SCTP实现中的sys/netinet/sctp_output.c文件中的‘sctp_send_initiate_ack’函数中存在安全漏洞,该漏洞源于程序没有正确初始化state-cookie数据结构。远程攻击者可通过读取INIT-ACK块中的数据包,利用该漏洞获得
CVSS Information
N/A
Vulnerability Type
N/A