PT-2017-7891 · Open Vswitch · Openvswitch

Bhargava Shastry

+1

·

Publicado

2017-05-29

·

Atualizado

2017-06-08

·

CVE-2016-10377

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open vSwitch version 2.5.0
Description A malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in the function miniflow extract in lib/flow.c, permitting remote bypass of the access control list enforced by the switch.
Recommendations For Open vSwitch version 2.5.0, consider disabling the miniflow extract function in lib/flow.c as a temporary workaround until a patch is available. Restrict access to the switch to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10377

Produtos afetados

Openvswitch