Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14970

Опубликовано: 02 окт. 2017
Источник: debian
EPSS Низкий

Описание

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvswitchfixed2.8.1+dfsg1-1experimentalpackage
openvswitchfixed2.8.1+dfsg1-2package

Примечания

  • https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339085.html

  • https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339086.html

  • Not considered a security issue by upstream, see #877543

EPSS

Процентиль: 67%
0.01244
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 2.2
redhat
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 5.9
nvd
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

suse-cvrf
почти 9 лет назад

Security update for openvswitch

suse-cvrf
почти 9 лет назад

Security update for openvswitch

EPSS

Процентиль: 67%
0.01244
Низкий