CVE-2015-8011 — Classic Buffer Overflow in Project Lldpd
Severity
9.8CRITICALNVD
EPSS
4.2%
top 11.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateMay 24
Description
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages3 packages
Also affects: Debian Linux 10.0, 9.0, Fedora 33
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-9f79-mcm7-48p3: Buffer overflow in the lldp_decode function in daemon/protocols/lldp↗2022-05-24
CVEList
▶