Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14970

Опубликовано: 02 окт. 2017
Источник: debian
EPSS Низкий

Описание

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvswitchfixed2.8.1+dfsg1-1experimentalpackage
openvswitchfixed2.8.1+dfsg1-2package

Примечания

  • https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339085.html

  • https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339086.html

  • Not considered a security issue by upstream, see #877543

EPSS

Процентиль: 70%
0.00651
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 2.2
redhat
больше 8 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 5.9
nvd
больше 8 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

suse-cvrf
около 8 лет назад

Security update for openvswitch

suse-cvrf
около 8 лет назад

Security update for openvswitch

EPSS

Процентиль: 70%
0.00651
Низкий