Back to Database
Status published
Critical
CVE-2006-1857
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows...
Vulnerability Description
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-1857
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.novell.com/linux/security/advisories/2006_42_kernel.html
- http://www.vupen.com/english/advisories/2006/2554
- http://secunia.com/advisories/20716
- http://www.vupen.com/english/advisories/2006/1893
- http://secunia.com/advisories/21476
- http://www.novell.com/linux/security/advisories/2006_47_kernel.html
- http://www.osvdb.org/25695
- http://www.securityfocus.com/bid/18085
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:150
- http://www.ubuntu.com/usn/usn-302-1
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:123
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10622
- http://www.debian.org/security/2006/dsa-1097
- http://www.redhat.com/support/errata/RHSA-2006-0575.html
- http://secunia.com/advisories/20185
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26584
- http://www.debian.org/security/2006/dsa-1103
- http://secunia.com/advisories/21465
- http://secunia.com/advisories/21498
- http://secunia.com/advisories/21045
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm
- http://secunia.com/advisories/22417
- http://secunia.com/advisories/20671
- http://secunia.com/advisories/21179
- http://secunia.com/advisories/20914
More from linux
View All →CVE-2022-48619
An issue was discovered in drivers/input/input.c in the Linux kernel...
Unknown
0
CVE-2022-48502
An issue was discovered in the Linux kernel before 6.2....
High
7.1
CVE-2022-48425
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid...
Unknown
0
CVE-2022-48424
In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate...
Unknown
0
CVE-2022-48423
In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate...
Unknown
0
Affected Vendor
linux
View all reports →Affected Software
linux kernel
Vulnerable Versions:
2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9, 2.6.10, 2.6.11, 2.6.11.5, 2.6.11.6, 2.6.11.7, 2.6.11.8, 2.6.11.11, 2.6.11.12, 2.6.12, 2.6.12.1, 2.6.12.2, 2.6.12.3, 2.6.12.4, 2.6.12.5, 2.6.12.6, 2.6.13, 2.6.13.1, 2.6.13.2, 2.6.13.3, 2.6.13.4, 2.6.14, 2.6.14.1, 2.6.14.2, 2.6.14.3, 2.6.14.4, 2.6.14.5, 2.6.15, 2.6.15.1, 2.6.15.2, 2.6.15.3, 2.6.15.4, 2.6.15.5, 2.6.16, 2.6.16.1, 2.6.16.2, 2.6.16.3, 2.6.16.4, 2.6.16.5, 2.6.16.6, 2.6.16.7, 2.6.16.8, 2.6.16.9, 2.6.16.10, 2.6.16.11, 2.6.16.12, 2.6.16.13, 2.6.16.14, 2.6.16.15, 2.6.16.16, 2.6_test9_cvs
Timeline
Official Publish:
May 22nd, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.