First published: Mon Dec 02 2019(Updated: )
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openslp-dfsg | ||
Openslp Openslp | =1.2.1 | |
Debian Debian Linux | =8.0 | |
Fedoraproject Fedora | =20 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4428 is a vulnerability in the openslp package that affects the SLPIntersectStringList() function and can lead to a denial of service (DoS) attack.
CVE-2012-4428 has a severity value of 7.5, which is considered high.
The openslp-dfsg package on Debian, Openslp 1.2.1, Debian Linux 8.0, Fedora 20, Canonical Ubuntu Linux 12.04, and Canonical Ubuntu Linux 14.04 are all affected by CVE-2012-4428.
There is currently no known fix for CVE-2012-4428. It is recommended to contact the software vendor or maintainers for possible updates or patches.
The CWE identifier for CVE-2012-4428 is CWE-125, which represents Out-of-bounds Read.