In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.
2020-05-13T16:15:12.620
2024-11-21T04:29:39.763
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |