In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openvswitchUpgrade openvswitch-ovn-centralUpgrade openvswitch-develUpgrade openvswitch-ovn-commonUpgrade openvswitch-ovn-dockerUpgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-hostUpgrade python-openvswitchUpgrade openvswitch-testUpgrade openvswitch-debuginfo | Aug 28, 2019 | May 23, 2017 |
| Debian | — | Upgrade openvswitch | Feb 22, 2021 | May 23, 2017 |
| Redhat_linux | — | Upgrade python-openvswitchUpgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-hostUpgrade openvswitch-ovn-commonUpgrade openvswitchUpgrade openvswitch-ovn-dockerUpgrade openvswitch-testUpgrade openvswitch-debuginfoUpgrade openvswitch-ovn-centralUpgrade openvswitch-devel | Aug 9, 2017 | May 23, 2017 |
| Suse | — | Upgrade openvswitch-switchUpgrade openvswitch-dpdkUpgrade openvswitch-dpdk-switchUpgrade openvswitch | Feb 4, 2018 | May 23, 2017 |
| Ubuntu | — | Upgrade openvswitch-common | Oct 11, 2017 | May 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub