Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kashyap Thimmaraju

Researcher fromsec.t-labs.tu-berlin.de
#16196of 53,633
16.6Total CVSS
Vulnerabilities · 2
High
2
PT-2017-7209
7.8
2017-08-24
Open Networking Operating System · Onos · CVE-2015-7516
**Name of the Vulnerable Software and Affected Versions** ONOS versions prior to 1.5.0 **Description** The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and switch disconnect, by sending two Ethernet frames with ether type Jumbo Frame (0x8870). **Recommendations** For versions prior to 1.5.0, update to version 1.5.0 or later to resolve the issue.
PT-2017-7891
8.8
2017-05-29
Open Vswitch · Openvswitch · CVE-2016-10377
**Name of the Vulnerable Software and Affected Versions** Open vSwitch version 2.5.0 **Description** A malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in the function `miniflow extract` in `lib/flow.c`, permitting remote bypass of the access control list enforced by the switch. **Recommendations** For Open vSwitch version 2.5.0, consider disabling the `miniflow extract` function in `lib/flow.c` as a temporary workaround until a patch is available. Restrict access to the switch to minimize the risk of exploitation.