CVE-2006-2272: High severity lksctp Stream Control Transmission Protocol vulnerability
Published May 9, 2006
·Updated
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIEECHO and (2) HEARTBEAT SCTP control chunks.
Affected Software
1 affected component
lksctp Stream Control Transmission Protocol<=2.6.16
Remediation
Patch Available
Patch Available
Event History
May 9, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2272?
CVE-2006-2272 has a high severity rating because it allows remote attackers to trigger a kernel panic, causing a denial of service.
2
How do I fix CVE-2006-2272?
To fix CVE-2006-2272, upgrade to a version of the Linux SCTP (lksctp) that is 2.6.17 or later.
3
What systems are affected by CVE-2006-2272?
CVE-2006-2272 affects Linux SCTP implementations before version 2.6.17.
4
What types of attacks does CVE-2006-2272 involve?
CVE-2006-2272 involves denial of service attacks through specially crafted IP fragmented COOKIE_ECHO and HEARTBEAT SCTP control chunks.
5
Is CVE-2006-2272 exploitable over the network?
Yes, CVE-2006-2272 is exploitable remotely, as it requires the attacker to send malicious SCTP packets to the vulnerable system.