PT-2015-6792 · Openslp+3 · Openslp+3

Qinghao Tang

·

Publicado

2015-08-07

·

Atualizado

2018-11-28

·

CVE-2015-5177

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSLP version 1.2.1 VMware ESXi (affected versions not specified)
Description The issue is related to a double free vulnerability in the SLPDKnownDAAdd function and a double free flaw in OpenSLP's SLPDProcessMessage() function. This could allow remote attackers to cause a denial of service (crash) or potentially execute code remotely on the ESXi host.
Recommendations For OpenSLP version 1.2.1, consider disabling the SLPDKnownDAAdd function as a temporary workaround until a patch is available. For VMware ESXi, restrict access to the SLPDProcessMessage() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2713
CVE-2015-5177
DLA-304-1
DSA-3353-1
USN-2730-1

Produtos afetados

Alt Linux
Openslp
Ubuntu
Vmware Esxi