REDHAT-BUG-1457329: Medium severity open vswitch vulnerability
In lib/conntrack.c in the firewall implementation in Open vSwitch, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions extractl3ipv6, extractl4tcp, and extractl4udp that can be triggered remotely.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1457329?
The severity of REDHAT-BUG-1457329 is classified as important due to the potential for remote exploitation.
How do I fix REDHAT-BUG-1457329?
To fix REDHAT-BUG-1457329, you should update Open vSwitch to the latest version that contains the security patch.
What systems are affected by REDHAT-BUG-1457329?
REDHAT-BUG-1457329 affects systems running Open vSwitch, particularly in configurations utilizing TCP, UDP, and IPv6.
Can REDHAT-BUG-1457329 be exploited remotely?
Yes, REDHAT-BUG-1457329 can be exploited remotely by sending malformed TCP, UDP, or IPv6 packets.
What type of vulnerability is REDHAT-BUG-1457329?
REDHAT-BUG-1457329 is a buffer over-read vulnerability in the Open vSwitch firewall implementation.