PT-2018-2465 · Open Vswitch+3 · Openvswitch+3

Publicado

2018-08-15

·

Atualizado

2021-08-04

·

CVE-2018-17204

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open vSwitch (OvS) versions 2.7.x through 2.7.6
Description An issue was discovered in Open vSwitch (OvS), affecting the parse group prop ntr selection method function in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. However, the OF1.5 decoder tries to use the type and command earlier, when it might still be invalid, causing an assertion failure via OVS NOT REACHED. This issue can be exploited by a remote attacker to cause a denial of service.
Recommendations For Open vSwitch (OvS) versions 2.7.x through 2.7.6, consider disabling support for OpenFlow 1.5 until a patch is available, as ovs-vswitchd does not enable it by default. As a temporary workaround, restrict the use of the parse group prop ntr selection method function in lib/ofp-util.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Assertion Failure

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2159
BDU:2019-00706
CVE-2018-17204
DLA-2571-1
OPENSUSE-SU-2018_4148-1
RHSA-2018:3500
RHSA-2019:0053
RHSA-2019:0081
SUSE-SU-2018:4128-1
SUSE-SU-2018_4128-1
USN-3873-1

Produtos afetados

Alt Linux
Openvswitch
Suse
Ubuntu