Open vSwitch Multiple Security Vulnerabilities
BID:102342
Info
Open vSwitch Multiple Security Vulnerabilities
| Bugtraq ID: | 102342 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-9265 CVE-2017-9263 CVE-2017-9264 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2017 12:00AM |
| Updated: | May 26 2017 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Redhat RHEV-M 4.0 Redhat OpenStack Platform 8.0 Redhat OpenStack Platform 11 Redhat OpenStack Platform 10 Redhat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Redhat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 Redhat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Open vSwitch Open vSwitch 2.7 IBM PowerKVM 3.1 |
| Not Vulnerable: | |
Discussion
Open vSwitch Multiple Security Vulnerabilities
Open vSwitch is prone to the following multiple security vulnerabilities:
1. Multiple buffer-overflow vulnerabilities
2. A denial-of-service vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Open vSwitch is prone to the following multiple security vulnerabilities:
1. Multiple buffer-overflow vulnerabilities
2. A denial-of-service vulnerability
An attacker can exploit these issues to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Open vSwitch Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Open vSwitch Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Open vSwitch Multiple Security Vulnerabilities
References:
References:
- Bug 1457327 - (CVE-2017-9263) CVE-2017-9263 openvswitch: Invalid processing of a (Red Hat Bugzilla)
- Bug 1457335 - (CVE-2017-9265) CVE-2017-9265 openvswitch: Buffer over-read while (Red Hat Bugzilla)
- CVE-2017-9263 (Red Hat Bugzilla)
- CVE-2017-9264 (Red Hat Bugzilla)
- CVE-2017-9265 (Red Hat Bugzilla)
- IBM Homepage (IBM)
- Bug 1457329 - (CVE-2017-9264) CVE-2017-9264 openvswitch: Buffer over-read while (Red Hat Bugzilla)
- isg3T1026032:Vulnerabilities in OpenvSwitch affect PowerKVM (ibm)