Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14970

Опубликовано: 02 окт. 2017
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
Версия до 2.8.0 (включая)

EPSS

Процентиль: 68%
0.01244
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-772

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 2.2
redhat
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

CVSS3: 5.9
debian
почти 9 лет назад

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multip ...

suse-cvrf
почти 9 лет назад

Security update for openvswitch

suse-cvrf
почти 9 лет назад

Security update for openvswitch

EPSS

Процентиль: 68%
0.01244
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-772