PT-2023-1101 · Unknown+6 · Openvswitch+6

Qian Chen

·

Published

2022-12-31

·

Updated

2023-11-26

·

CVE-2022-4337

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenvSwitch (affected versions not specified)
Description The issue is related to an out-of-bounds read in Organization Specific TLV found in OpenvSwitch. It can be exploited by sending specially crafted LLDP messages to the vulnerable system, potentially allowing remote attackers to execute arbitrary code. The vulnerability is also associated with an integer overflow when parsing Auto Attach TLV.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1745
ALT-PU-2023-1806
AZL-12952
BDU:2023-00290
CVE-2022-4337
DLA-3253-1
DSA-5319-1
OPENSUSE-SU-2023_2250-2
RHSA-2023:0685
RHSA-2023:0687
RHSA-2023:0688
RHSA-2023:0689
RHSA-2023:0691
ROSA-SA-2023-2262
SUSE-SU-2023:2250-1
SUSE-SU-2023:2250-2
SUSE-SU-2023:2251-1
SUSE-SU-2023:2255-1
SUSE-SU-2023:2259-1
SUSE-SU-2023:2274-1
SUSE-SU-2023:2275-1
SUSE-SU-2023:2360-1
SUSE-SU-2023_2250-1
SUSE-SU-2023_2251-1
SUSE-SU-2023_2274-1
SUSE-SU-2023_2275-1
USN-5890-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openvswitch
Red Os
Suse
Ubuntu