Candidate: CVE-2008-4445 PublicDate: 2008-10-06 19:54:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4445 https://ubuntu.com/security/notices/USN-659-1 Description: The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bounds established by SCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function, a different vulnerability than CVE-2008-4113. Ubuntu-Description: Notes: kees> The linked patch fixes this and CVE-2008-4113 Bugs: Priority: low Discovered-by: Assigned-to: smb_tp CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: not-affected (code not present) dapper_linux-source-2.6.15: not-affected (code not present) feisty_linux-source-2.6.15: DNE gutsy_linux-source-2.6.15: DNE hardy_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux-source-2.6.20: upstream_linux-source-2.6.20: not-affected (code not present) dapper_linux-source-2.6.20: DNE feisty_linux-source-2.6.20: not-affected (code not present) gutsy_linux-source-2.6.20: DNE hardy_linux-source-2.6.20: DNE devel_linux-source-2.6.20: DNE Patches_linux-source-2.6.22: upstream_linux-source-2.6.22: not-affected (code not present) dapper_linux-source-2.6.22: DNE feisty_linux-source-2.6.22: DNE gutsy_linux-source-2.6.22: not-affected (code not present) hardy_linux-source-2.6.22: DNE devel_linux-source-2.6.22: DNE Patches_linux: upstream_linux: released (2.6.27) dapper_linux: DNE feisty_linux: DNE gutsy_linux: DNE hardy_linux: released (2.6.24-21.43) devel_linux: not-affected