Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.
A double free flaw was found in openslp's SLPDProcessMessage() function. A crafted package could cause openslp to crash.
This flaw only affects version 1.2.1 of openslp, which is only shipped in EPEL 5. Version 2.0.0 is not affected.
OpenSLP is not actively maintained upstream so patches are not available.
Acknowledgements:
Red Hat would like to thank Qinghao Tang of QIHU 360 for reporting this issue.
The extension parser in slpv2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of service (infinite loop) via a packet with a "next extension offset" that references this extension or a previous extension. NOTE: some of these details are obtained from third party information.