OpenSLP Extension Parser Remote Denial Of Service Vulnerability
BID:46772
Info
OpenSLP Extension Parser Remote Denial Of Service Vulnerability
| Bugtraq ID: | 46772 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-3609 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 07 2011 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Nicolas Gregoire, US CERT. |
| Vulnerable: |
VMWare ESXi Server 4.1 VMWare ESXi Server 4.0 VMWare ESX Server 4.1 VMWare ESX Server 4.0 Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.10 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 LTS Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 11 SuSE SUSE Linux Enterprise 11 SuSE openSUSE 11.3 SuSE Linux 11 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 OpenSLP OpenSLP 1.2.1 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
VMWare ESXi Server 4.1 ESXi410-20110120 VMWare ESXi Server 4.0 ESXi400-20110340 VMWare ESX Server 4.1 ESX410-201101201 VMWare ESX Server 4.0 ESX400-201103401 |
Discussion
OpenSLP Extension Parser Remote Denial Of Service Vulnerability
OpenSLP is prone to a remote denial-of-service vulnerability that affects the extension parser.
An attacker can cause the extension parser to enter an infinite loop, consume CPU resources, and trigger a denial-of-service condition.
NOTE: This BID was previously titled 'VMware ESX/ESXi Service Location Protocol Daemon Local Denial Of Service Vulnerability', but has been rewritten to better document that the underlying vulnerability occurs in OpenSLP.
OpenSLP is prone to a remote denial-of-service vulnerability that affects the extension parser.
An attacker can cause the extension parser to enter an infinite loop, consume CPU resources, and trigger a denial-of-service condition.
NOTE: This BID was previously titled 'VMware ESX/ESXi Service Location Protocol Daemon Local Denial Of Service Vulnerability', but has been rewritten to better document that the underlying vulnerability occurs in OpenSLP.
Exploit / POC
OpenSLP Extension Parser Remote Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
OpenSLP Extension Parser Remote Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenSLP Extension Parser Remote Denial Of Service Vulnerability
References:
References:
- Audit partiel des composants Open Source intégrés à VMware ESX (SLP) (Nicolas Grégoire)
- CVE-2010-3609 (Novell)
- SCM Repositories - openslp (OpenSLP)
- VMware Homepage (VMware)
- VMWare Security Advisory: VMSA-2011-0004 (VMWare)
- VU#393783 OpenSLP denial of service vulnerability (US-CERT)