CVE-2015-8011Classic Buffer Overflow in Project Lldpd

Severity
9.8CRITICALNVD
EPSS
4.2%
top 11.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateMay 24

Description

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDlldpd_project/lldpd0.5.60.8.0
Debianlldpd_project/lldpd< 0.7.19-1+3
Debianopenvswitch/openvswitch< 2.15.0~git20210104.def6eb1ea+dfsg1-1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 33

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9f79-mcm7-48p3: Buffer overflow in the lldp_decode function in daemon/protocols/lldp2022-05-24
OSV
CVE-2015-8011: Buffer overflow in the lldp_decode function in daemon/protocols/lldp2020-01-28
CVEList
CVE-2015-8011: Buffer overflow in the lldp_decode function in daemon/protocols/lldp2020-01-28

📋Vendor Advisories

3
Ubuntu
Open vSwitch vulnerabilities2021-01-13
Red Hat
lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c2015-10-15
Debian
CVE-2015-8011: lldpd - Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd ...2015