packetstormsecurity.com
http://packetstormsecurity.com/files/135369/FreeBSD-SCTP-ICMPv6-Denial-Of-Service.html CVE-2016-1879
HIGH
FreeBSD SCTP ICMPv6 - Error Processing
Record summary
CVE-2016-1879 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFreeBSD SCTP ICMPv6 - Error ProcessingExploitDB exploitby ptsecurityNot analyzed1 file
References
51034673vdb entry
http://www.securitytracker.com/id/1034673 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-1879 39305exploit
https://www.exploit-db.com/exploits/39305 FreeBSD-SA-16:01Vendor advisory
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:01.sctp.asc