Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9263

Опубликовано: 26 мая 2017
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function ofp_print_role_status_message in lib/ofp-print.c that may be leveraged toward a remote DoS attack by a malicious switch.

While parsing an OpenFlow role status message Open vSwitch (OvS), a call to the abort() function for undefined role status reasons in the function 'ofp_print_role_status_message' in 'lib/ofp-print.c' could be misused for a remote denial of service attack by a malicious switch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openvswitchWill not fix
Red Hat OpenShift Enterprise 3openvswitchNot affected
Red Hat OpenStack Platform 12 (Pike)openvswitchNot affected
Fast Datapath for Red Hat Enterprise Linux 7openvswitchFixedRHSA-2017:241803.08.2017
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openvswitchFixedRHSA-2017:266506.09.2017
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7openvswitchFixedRHSA-2017:269812.09.2017
Red Hat OpenStack Platform 10.0 (Newton)openvswitchFixedRHSA-2017:264806.09.2017
Red Hat OpenStack Platform 11.0 (Ocata)openvswitchFixedRHSA-2017:272713.09.2017
Red Hat OpenStack Platform 8.0 (Liberty)openvswitchFixedRHSA-2017:269212.09.2017
Red Hat OpenStack Platform 9.0 (Mitaka)openvswitchFixedRHSA-2017:255330.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1457327openvswitch: Invalid processing of a malicious OpenFlow role status message

EPSS

Процентиль: 48%
0.00248
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.

CVSS3: 6.5
nvd
больше 8 лет назад

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.

CVSS3: 6.5
debian
больше 8 лет назад

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status mes ...

CVSS3: 6.5
github
больше 3 лет назад

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.

suse-cvrf
больше 8 лет назад

Security update for openvswitch

EPSS

Процентиль: 48%
0.00248
Низкий

5.9 Medium

CVSS3