REDHAT-BUG-2453459: Medium severity Open vSwitch Open vSwitch vulnerability
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2453459?
The severity of REDHAT-BUG-2453459 is medium with a score of 4.
How do I fix REDHAT-BUG-2453459?
To fix REDHAT-BUG-2453459, update Open vSwitch to the latest patched version released by the vendor.
What components are affected by REDHAT-BUG-2453459?
REDHAT-BUG-2453459 affects Open vSwitch when configured with conntrack flow using FTP helpers.
What kind of attack does REDHAT-BUG-2453459 expose systems to?
REDHAT-BUG-2453459 exposes systems to remote crashes caused by specially crafted FTP streams.
What impact does REDHAT-BUG-2453459 have on systems?
The impact of REDHAT-BUG-2453459 includes potential crashes due to heap access errors.