CVE-2012-4428
published 2019-12-02CVE-2012-4428: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
9.57%
94.9th percentile
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| openslp-dfsg | openslp-dfsg | — | — |
| openslp-dfsg | openslp-dfsg | >= 0 < 1.2.1-9ubuntu0.2 | 1.2.1-9ubuntu0.2 |
| openslp | openslp | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x95h-4fhf-p9gw: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
ghsa_unreviewed·2022-04-23
CVE-2012-4428 [MEDIUM] GHSA-x95h-4fhf-p9gw: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
OSV
openslp-dfsg vulnerabilities
osv·2015-09-03·CVSS 7.5
CVE-2012-4428 [HIGH] openslp-dfsg vulnerabilities
openslp-dfsg vulnerabilities
Georgi Geshev discovered that OpenSLP incorrectly handled processing
certain service requests. A remote attacker could possibly use this issue
to cause OpenSLP to crash, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2012-4428)
Qinghao Tang discovered that OpenSLP incorrectly handled processing certain
messages. A remote attacker could possibly use this issue to cause
OpenSLP to crash, resulting in a denial of service. (CVE-2015-5177)
OSV
CVE-2012-4428: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
osv·2012-09-13·CVSS 7.5
CVE-2012-4428 [HIGH] CVE-2012-4428: openslp: SLPIntersectStringList()' Function has a DoS vulnerability
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
Ubuntu
OpenSLP vulnerabilities
vendor_ubuntu·2015-09-03·CVSS 7.5
CVE-2012-4428 [HIGH] OpenSLP vulnerabilities
Title: OpenSLP vulnerabilities
Summary: OpenSLP could be made to crash if it received specially crafted network
traffic.
Georgi Geshev discovered that OpenSLP incorrectly handled processing
certain service requests. A remote attacker could possibly use this issue
to cause OpenSLP to crash, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2012-4428)
Qinghao Tang discovered that OpenSLP incorrectly handled processing certain
messages. A remote attacker could possibly use this issue to cause
OpenSLP to crash, resulting in a denial of service. (CVE-2015-5177)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
vendor_redhat·2012-09-13·CVSS 7.5
CVE-2012-4428 [HIGH] CWE-125 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
Statement: Not vulnerable. This issue did not affect the versions of openslp as shipped with Red Hat Enterprise Linux 6.
Package: openslp (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [fedora-all]
bugzilla·2012-09-13·CVSS 7.5
CVE-2012-4428 [HIGH] CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [fedora-all]
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/update
Bugzilla
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [epel-5]
bugzilla·2012-09-13·CVSS 7.5
CVE-2012-4428 [HIGH] CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [epel-5]
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/ne
Bugzilla
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
bugzilla·2012-09-13·CVSS 7.5
CVE-2012-4428 [HIGH] CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS
An out-of-bounds read error was reported [1] in OpenSLP's SLPIntersectStringList() function (in common/sip_compare.c) when processing service requests. This could be exploited to cause a crash via a specially-crafted request. The report is against version 1.2.1, however other versions may be affected.
There is not yet any upstream patch or bug report.
[1] https://secunia.com/advisories/50130/
Discussion:
Created openslp tracking bugs for this issue
Affects: fedora-all [bug 857245]
---
Created openslp tracking bugs for this issue
Affects: epel-5 [bug 857247]
---
The CVE identifier of CVE-2012-4428 has been assigned to this issue:
http://www.openwall.com/lists/oss-security/2012/09/13/27
---
Upstr
Tenable
Nessus 5.0.2 Available
blogs_tenable·2012-10-10·CVSS 5.3
[MEDIUM] Nessus 5.0.2 Available
Blog /
Subscribe
# Nessus 5.0.2 Available
Ron Gula
October 10, 2012
0 Min Read
Nessus 5.0.2 has been released and is available at http://www.nessus.org/download/. This update is largely a bugfix release, however a new build for Solaris 10 is now available.
The major issues addressed in 5.0.2 include enhanced support for UTF8 encoding problems in reports and the detection of network congestion errors during scans more conservatively. For a full list of addressed issues, please review the 5.0.2 availability announcement at the Nessus Discussion Forums.
## Related articles
May 13, 2025
## CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution
Remote code execution vulnerability in a popular mobile device management solution from Ivanti has been exp
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159059.htmlhttp://www.openwall.com/lists/oss-security/2012/09/13/27http://www.securityfocus.com/bid/55540http://www.ubuntu.com/usn/USN-2730-1https://access.redhat.com/security/cve/cve-2012-4428https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4428https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-4428https://exchange.xforce.ibmcloud.com/vulnerabilities/78732https://security-tracker.debian.org/tracker/CVE-2012-4428https://security.gentoo.org/glsa/201707-05http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159059.htmlhttp://www.openwall.com/lists/oss-security/2012/09/13/27http://www.securityfocus.com/bid/55540http://www.ubuntu.com/usn/USN-2730-1https://access.redhat.com/security/cve/cve-2012-4428https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4428https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-4428https://exchange.xforce.ibmcloud.com/vulnerabilities/78732https://security-tracker.debian.org/tracker/CVE-2012-4428https://security.gentoo.org/glsa/201707-05
2019-12-02
Published