[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-14970 -- openvswitch

ID: oval:org.secpod.oval:def:2000511Date: (C)2019-06-02   (M)2023-04-19
Class: VULNERABILITYFamily: unix




In lib/ofp-util.c in Open vSwitch before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

Platform:
Debian 8.x
Debian 9.x
Product:
openvswitch-common
Reference:
CVE-2017-14970
CVE    1
CVE-2017-14970
CPE    3
cpe:/a:openvswitch.org:openvswitch-common
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies