CVE-2012-4428: High severity OpenSLP OpenSLP vulnerability
Published Dec 2, 2019
·Updated
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
Affected Software
6 affected components
debian/openslp-dfsg
OpenSLP OpenSLP=1.2.1
Debian Debian Linux=8.0
Fedoraproject Fedora=20
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Event History
Dec 2, 2019
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·02:05 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2012-4428?
CVE-2012-4428 is a vulnerability in the openslp package that affects the SLPIntersectStringList() function and can lead to a denial of service (DoS) attack.
2
What is the severity of CVE-2012-4428?
CVE-2012-4428 has a severity value of 7.5, which is considered high.
3
Which software is affected by CVE-2012-4428?
The openslp-dfsg package on Debian, Openslp 1.2.1, Debian Linux 8.0, Fedora 20, Canonical Ubuntu Linux 12.04, and Canonical Ubuntu Linux 14.04 are all affected by CVE-2012-4428.
4
How can I fix CVE-2012-4428?
There is currently no known fix for CVE-2012-4428. It is recommended to contact the software vendor or maintainers for possible updates or patches.
5
What is the Common Weakness Enumeration (CWE) identifier for CVE-2012-4428?
The CWE identifier for CVE-2012-4428 is CWE-125, which represents Out-of-bounds Read.