Vulnerabilities > CVE-2012-3549 - Remote Denial of Service vulnerability in Freebsd 8.2

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
freebsd
exploit available

Summary

The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk. Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference'

Vulnerable Configurations

Part Description Count
OS
Freebsd
1

Exploit-Db

descriptionFreeBSD Kernel SCTP Remote NULL Ptr Dereference DoS. CVE-2012-3549. Dos exploit for freebsd platform
fileexploits/freebsd/dos/20226.c
idEDB-ID:20226
last seen2016-02-02
modified2012-08-03
platformfreebsd
port
published2012-08-03
reporterShaun Colley
sourcehttps://www.exploit-db.com/download/20226/
titleFreeBSD Kernel SCTP Remote NULL Ptr Dereference DoS
typedos