cbcvebase.
CVE-2017-17833
published 2018-04-23

CVE-2017-17833: OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
lenovobm_nextscale_fan_power_controller< 24p-2.1524p-2.15
lenovocmm< 1.8.01.8.0
lenovofan_power_controller< 30r-1.1330r-1.13
lenovoflex_system_fc3171_8gb_san_switch_firmware< 9.1.13.02.009.1.13.02.00
lenovoimm1< 1.551.55
lenovoimm2< 4.704.70
lenovostorage_n3310_firmware< 4.53.3514.53.351
lenovostorage_n4610_firmware< 4.53.3514.53.351
lenovothinkserver_rd340_firmware< 50.0050.00
lenovothinkserver_rd350_firmware< 4.53.3514.53.351
lenovothinkserver_rd440_firmware<= 50.00
lenovothinkserver_rd450_firmware< 4.53.3514.53.351
lenovothinkserver_rd540_firmware< 50.0050.00
lenovothinkserver_rd550_firmware< 4.53.3514.53.351
lenovothinkserver_rd640_firmware< 50.0050.00
lenovothinkserver_rd650_firmware< 4.53.3514.53.351
lenovothinkserver_rq750_firmware< 1.401.40
lenovothinkserver_rs160_firmware< 2.322.32
lenovothinkserver_td340_firmware< 46.0046.00
lenovothinkserver_td350_firmware< 4.53.3514.53.351
lenovothinkserver_ts460_firmware< 2.322.32
lenovoxclarity_administrator< 1.4.01.4.0

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL