[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-17204 -- openvswitch

ID: oval:org.secpod.oval:def:2000673Date: (C)2019-04-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




An issue was discovered in Open vSwitch 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure . ovs-vswitchd does not enable support for OpenFlow 1.5 by default.

Platform:
Debian 9.x
Product:
openvswitch-common
Reference:
CVE-2018-17204
CVE    1
CVE-2018-17204
CPE    2
cpe:/a:openvswitch.org:openvswitch-common
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies