Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8011

Опубликовано: 15 окт. 2015
Источник: redhat
CVSS3: 9.8

Описание

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

A buffer overflow was found in the lldp_decode function in daemon/protocols/lldp.c in lldpd. This flaw allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries. This threatens the system's confidentiality, integrity, and availability.

Отчет

The lldpd package as shipped with Red Hat Enterprise Linux 8 is not affected by this flaw because it has already received the patch. The flaw affects versions before 0.8.0 and the shipped version is 1.0.1+. In addition, Red Hat Virtualization 4.3 manager appliance is out of support scope and therefore no fix for it will be delivered.

Меры по смягчению последствий

When the lldpd source is compiled with source fortification enabled, the flaw becomes unexploitable and will just cause a crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitch2.10Out of support scope
Fast Datapath for RHEL 7openvswitch2.12Out of support scope
Fast Datapath for RHEL 8openvswitch2.12Out of support scope
Red Hat Enterprise Linux 8lldpdNot affected
Red Hat Virtualization 4rhv-openvswitchNot affected
Fast Datapath for Red Hat Enterprise Linux 7openvswitch2.13FixedRHBA-2020:530601.12.2020
Fast Datapath for Red Hat Enterprise Linux 7openvswitch2.11FixedRHBA-2020:530701.12.2020
Fast Datapath for Red Hat Enterprise Linux 7openvswitchFixedRHSA-2021:207720.05.2021
Fast Datapath for Red Hat Enterprise Linux 8openvswitch2.13FixedRHBA-2020:531001.12.2020
Fast Datapath for Red Hat Enterprise Linux 8openvswitch2.11FixedRHBA-2020:531101.12.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1896536lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

CVSS3: 9.8
nvd
около 6 лет назад

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

CVSS3: 9.8
debian
около 6 лет назад

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c ...

github
больше 3 лет назад

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

CVSS3: 9.8
fstec
больше 10 лет назад

Уязвимость функции lldp_decode компонента daemon/protocols/lldp.c реализации протокола LLDP под Unix Lldpd, связанная с переполнением буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

9.8 Critical

CVSS3

Уязвимость CVE-2015-8011