Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-25076

Опубликовано: 08 сент. 2022
Источник: debian

Описание

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvswitchunfixedpackage
openvswitchpostponedtrixiepackage
openvswitchpostponedbookwormpackage
openvswitchno-dsabullseyepackage
openvswitchno-dsabusterpackage

Примечания

  • https://arxiv.org/abs/2011.09107

  • https://sites.google.com/view/tuple-space-explosion

  • https://dl.acm.org/doi/10.1145/3359989.3365431

  • https://www.youtube.com/watch?v=5cHpzVK0D28

  • https://www.youtube.com/watch?v=DSC3m-Bww64

Связанные уязвимости

CVSS3: 5.8
ubuntu
больше 3 лет назад

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.

CVSS3: 5.8
redhat
больше 3 лет назад

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.

CVSS3: 5.8
nvd
больше 3 лет назад

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.

CVSS3: 5.8
msrc
больше 3 лет назад

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache aka a Tuple Space Explosion (TSE) attack.

CVSS3: 5.8
github
больше 3 лет назад

The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.