CVE-2015-5177
published 2017-10-22CVE-2015-5177: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash)…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.31%
92.8th percentile
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| openslp-dfsg | openslp-dfsg | >= 0 < 1.2.1-9ubuntu0.2 | 1.2.1-9ubuntu0.2 |
| openslp | openslp | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3pvr-5fcv-fj5r: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda
ghsa_unreviewed·2022-05-17
CVE-2015-5177 [HIGH] CWE-415 GHSA-3pvr-5fcv-fj5r: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
OSV
openslp-dfsg vulnerabilities
osv·2015-09-03·CVSS 7.5
CVE-2012-4428 [HIGH] openslp-dfsg vulnerabilities
openslp-dfsg vulnerabilities
Georgi Geshev discovered that OpenSLP incorrectly handled processing
certain service requests. A remote attacker could possibly use this issue
to cause OpenSLP to crash, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2012-4428)
Qinghao Tang discovered that OpenSLP incorrectly handled processing certain
messages. A remote attacker could possibly use this issue to cause
OpenSLP to crash, resulting in a denial of service. (CVE-2015-5177)
OSV
CVE-2015-5177: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda
osv·2015-08-07·CVSS 7.5
CVE-2015-5177 [HIGH] CVE-2015-5177: Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
VMware
VMware vCenter and ESXi updates address critical security issues.
vendor_vmware·2015-10-01·CVSS 7.5
CVE-2015-1047 [HIGH] VMware vCenter and ESXi updates address critical security issues.
VMSA-2015-0007: VMware vCenter and ESXi updates address critical security issues.
a. VMware ESXi OpenSLP Remote Code Execution VMware ESXi contains a double free flaw in OpenSLP's SLPDProcessMessage() function. Exploitation of this issue may allow an unauthenticated attacker to remotely execute code on the ESXi host. VMware would like to thank Qinghao Tang of QIHU 360 for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-5177 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ===== Product Version ===== Running on ====== Replace with/ Apply Patch ================== VMware Product =====ESXi Product V
Ubuntu
OpenSLP vulnerabilities
vendor_ubuntu·2015-09-03·CVSS 7.5
CVE-2012-4428 [HIGH] OpenSLP vulnerabilities
Title: OpenSLP vulnerabilities
Summary: OpenSLP could be made to crash if it received specially crafted network
traffic.
Georgi Geshev discovered that OpenSLP incorrectly handled processing
certain service requests. A remote attacker could possibly use this issue
to cause OpenSLP to crash, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2012-4428)
Qinghao Tang discovered that OpenSLP incorrectly handled processing certain
messages. A remote attacker could possibly use this issue to cause
OpenSLP to crash, resulting in a denial of service. (CVE-2015-5177)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openslp: double free in SLPDProcessMessage()
vendor_redhat·2015-08-06·CVSS 7.5
CVE-2015-5177 [HIGH] CWE-416 openslp: double free in SLPDProcessMessage()
openslp: double free in SLPDProcessMessage()
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
Package: openslp (Red Hat Enterprise Linux 6) - Not affected
Package: openslp (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
Bugzilla
CVE-2015-5177 openslp: double free in SLPDProcessMessage()
bugzilla·2015-08-06·CVSS 7.5
CVE-2015-5177 [HIGH] CVE-2015-5177 openslp: double free in SLPDProcessMessage()
CVE-2015-5177 openslp: double free in SLPDProcessMessage()
A double free flaw was found in openslp's SLPDProcessMessage() function. A crafted package could cause openslp to crash.
This flaw only affects version 1.2.1 of openslp, which is only shipped in EPEL 5. Version 2.0.0 is not affected.
OpenSLP is not actively maintained upstream so patches are not available.
Acknowledgements:
Red Hat would like to thank Qinghao Tang of QIHU 360 for reporting this issue.
Discussion:
Additional details from Qinghao Tang:
Let`s see how this issue happened,the code below is from
/openslp-1.2.1/slpd/slpd_process.c and slpd_knownda.c:
int SLPDProcessMessage(struct sockaddr_in* peerinfo,
SLPBuffer recvbuf,
SLPBuffer* sendbuf)
{
...
message = SLPMessageAlloc();
if (message)
{
/* Parse the message a
http://sourceforge.net/p/openslp/mercurial/ci/2bc15d0494f886d9c4fe342d23bc160605aea51d/http://www.securityfocus.com/bid/76635http://www.securitytracker.com/id/1033719https://bugzilla.redhat.com/show_bug.cgi?id=1251064https://www.debian.org/security/2015/dsa-3353http://sourceforge.net/p/openslp/mercurial/ci/2bc15d0494f886d9c4fe342d23bc160605aea51d/http://www.securityfocus.com/bid/76635http://www.securitytracker.com/id/1033719https://bugzilla.redhat.com/show_bug.cgi?id=1251064https://www.debian.org/security/2015/dsa-3353
2017-10-22
Published