漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SCTP needs to better-check INIT ACK chunk parameters
Vulnerability Description
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/S:P/AU:Y/R:U/V:C/RE:H/U:Red
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
illumos illumos-gate 缓冲区错误漏洞
Vulnerability Description
illumos illumos-gate是illumos组织开源的一个开源 Unix 操作系统。 illumos illumos-gate存在缓冲区错误漏洞,该漏洞源于SCTP入站路径对INIT ACK数据块进行关联查找时未充分验证地址参数,可能导致远程、未验证的攻击者通过发送特制SCTP INIT ACK数据包触发越界访问和内核堆损坏,从而导致远程代码执行。以下版本受到影响:illumos-gate a5407c02版本至53a3efde版本、OmniOS r151058版本、r151056版本、r15
CVSS Information
N/A
Vulnerability Type
N/A