REDHAT-BUG-1457335: Medium severity open vswitch vulnerability
In Open vSwitch there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in lib/ofp-util.c in the function ofputilpullofp15groupmod.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332965.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1457335?
The severity of REDHAT-BUG-1457335 is classified as high due to the potential for buffer over-read vulnerabilities.
How do I fix REDHAT-BUG-1457335?
To fix REDHAT-BUG-1457335, update Open vSwitch to the latest version that includes the security patch.
What systems are affected by REDHAT-BUG-1457335?
REDHAT-BUG-1457335 affects all versions of Open vSwitch that are vulnerable to the buffer over-read issue.
What kind of vulnerability is REDHAT-BUG-1457335?
REDHAT-BUG-1457335 is a buffer over-read vulnerability that occurs while parsing the group mod OpenFlow message.
Is there a workaround for REDHAT-BUG-1457335?
There is no official workaround for REDHAT-BUG-1457335, and applying the relevant patches is the recommended action.