Описание
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Отчет
This vulnerability in Open vSwitch, leading to a heap access error and potential denial of service, is not exploitable in default Red Hat configurations. Exploitation requires Open vSwitch to be specifically configured with FTP helpers over the userspace datapath, which is not enabled by default.
Меры по смягчению последствий
Optionally, avoid using alg=ftp flows. These are not usually configured.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Fast Datapath for RHEL 7 | openvswitch | Fix deferred | ||
| Fast Datapath for RHEL 7 | openvswitch2.10 | Fix deferred | ||
| Fast Datapath for RHEL 7 | openvswitch2.11 | Fix deferred | ||
| Fast Datapath for RHEL 7 | openvswitch2.12 | Fix deferred | ||
| Fast Datapath for RHEL 7 | openvswitch2.13 | Fix deferred | ||
| Fast Datapath for RHEL 7 | openvswitch-selinux-extra-policy | Fix deferred | ||
| Fast Datapath for RHEL 7 | ovn2.11 | Fix deferred | ||
| Fast Datapath for RHEL 7 | ovn2.12 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.11 | Fix deferred | ||
| Fast Datapath for RHEL 8 | openvswitch2.12 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Openvswitch: open vswitch: denial of service via malformed ftp epasv command
A flaw was found in Open vSwitch. When Open vSwitch is configured with ...
EPSS
5.9 Medium
CVSS3