Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17833

Опубликовано: 19 апр. 2018
Источник: redhat
CVSS3: 7.5

Описание

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

A use-after-free flaw in OpenSLP 1.x and 2.x baselines was discovered in the ProcessSrvRqst function. A failure to update a local pointer may lead to heap corruption. A remote attacker may be able to leverage this flaw to gain remote code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8openslpNot affected
Red Hat Enterprise Linux 6openslpFixedRHSA-2018:230831.07.2018
Red Hat Enterprise Linux 7openslpFixedRHSA-2018:224023.07.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1572166openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

CVSS3: 9.8
nvd
больше 7 лет назад

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

CVSS3: 9.8
debian
больше 7 лет назад

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-relat ...

suse-cvrf
около 7 лет назад

Security update for openslp

suse-cvrf
больше 7 лет назад

Security update for openslp

7.5 High

CVSS3