[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99536

 
 

909

 
 

80128

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-9264

Date: (C)2017-05-30   (M)2018-01-05 


In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.

CVSS Score: 7.5Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
RHSA-2017:2418
RHSA-2017:2648
RHSA-2017:2727
https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html

CWE    1
CWE-119
OVAL    1
oval:org.secpod.oval:def:703843

© 2013 SecPod Technologies