CVE-2017-17833
published 2018-04-23CVE-2017-17833: OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.89%
89.1th percentile
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| lenovo | bm_nextscale_fan_power_controller | < 24p-2.15 | 24p-2.15 |
| lenovo | cmm | < 1.8.0 | 1.8.0 |
| lenovo | fan_power_controller | < 30r-1.13 | 30r-1.13 |
| lenovo | flex_system_fc3171_8gb_san_switch_firmware | < 9.1.13.02.00 | 9.1.13.02.00 |
| lenovo | imm1 | < 1.55 | 1.55 |
| lenovo | imm2 | < 4.70 | 4.70 |
| lenovo | storage_n3310_firmware | < 4.53.351 | 4.53.351 |
| lenovo | storage_n4610_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_rd340_firmware | < 50.00 | 50.00 |
| lenovo | thinkserver_rd350_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_rd440_firmware | <= 50.00 | — |
| lenovo | thinkserver_rd450_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_rd540_firmware | < 50.00 | 50.00 |
| lenovo | thinkserver_rd550_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_rd640_firmware | < 50.00 | 50.00 |
| lenovo | thinkserver_rd650_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_rq750_firmware | < 1.40 | 1.40 |
| lenovo | thinkserver_rs160_firmware | < 2.32 | 2.32 |
| lenovo | thinkserver_td340_firmware | < 46.00 | 46.00 |
| lenovo | thinkserver_td350_firmware | < 4.53.351 | 4.53.351 |
| lenovo | thinkserver_ts460_firmware | < 2.32 | 2.32 |
| lenovo | xclarity_administrator | < 1.4.0 | 1.4.0 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSLP vulnerabilities
vendor_ubuntu·2018-07-09
CVE-2017-17833 OpenSLP vulnerabilities
Title: OpenSLP vulnerabilities
Summary: OpenSLP could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that OpenSLP incorrectly handled certain memory
operations. A remote attacker could use this issue to cause OpenSLP to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
vendor_redhat·2018-06-28·CVSS 9.8
CVE-2018-12938 [CRITICAL] CWE-416 openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
No description is available for this CVE.
Statement: This flaw was found to be a duplicate of CVE-2017-17833. Please see https://access.redhat.com/security/cve/CVE-2017-17833 for information about affected products and security errata.
Package: openslp (Red Hat Enterprise Linux 6) - Not affected
Package: openslp (Red Hat Enterprise Linux 7) - Not affected
Package: openslp (Red Hat Enterprise Linux 8) - Not affected
Red Hat
openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
vendor_redhat·2018-04-19·CVSS 9.8
CVE-2017-17833 [CRITICAL] CWE-416 openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
A use-after-free flaw in OpenSLP 1.x and 2.x baselines was discovered in the ProcessSrvRqst function. A failure to update a local pointer may lead to heap corruption. A remote attacker may be able to leverage this flaw to gain remote code execution.
Package: openslp (Red Hat Enterprise Linux 8) - Not affected
GHSA
GHSA-r3mh-hjcg-756h: OpenSLP releases in the 1
ghsa_unreviewed·2022-05-13
CVE-2017-17833 [CRITICAL] CWE-119 GHSA-r3mh-hjcg-756h: OpenSLP releases in the 1
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
OSV
CVE-2017-17833: OpenSLP releases in the 1
osv·2018-04-23·CVSS 9.8
CVE-2017-17833 [CRITICAL] CVE-2017-17833: OpenSLP releases in the 1
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12938 openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
bugzilla·2018-06-29·CVSS 9.8
CVE-2018-12938 [CRITICAL] CVE-2018-12938 openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
CVE-2018-12938 openslp: Double free in slp_buffer:SLPBufferRealloc() may allow a remote attacker to execute arbitrary code
OpenSLP through version 2.0.0 is vulnerable to a double freeing of memory that causes a crash in the slp_buffer:SLPBufferRealloc() function. A remote unauthenticated attacker could exploit this to cause a denial of service or potentially execute arbitrary code.
Discussion:
Created openslp tracking bugs for this issue:
Affects: fedora-all [bug 1596451]
---
Possibly related to CVE-2017-17833
---
*** This bug has been marked as a duplicate of bug 1572166 ***
---
Statement:
This flaw was found to be a duplicate of CVE-2017-17833. Please see https://access.redhat.com/security/cve/CVE-2017-17833 for information about affected products and security errata.
Bugzilla
CVE-2017-17833 CVE-2018-12938 openslp: various flaws [fedora-all]
bugzilla·2018-04-26·CVSS 9.8
CVE-2017-17833 [CRITICAL] CVE-2017-17833 CVE-2018-12938 openslp: various flaws [fedora-all]
CVE-2017-17833 CVE-2018-12938 openslp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2017-17833 openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
bugzilla·2018-04-26·CVSS 9.8
CVE-2017-17833 [CRITICAL] CVE-2017-17833 openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
CVE-2017-17833 openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution
OpenSLP releases have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Upstream patch:
https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/
Discussion:
Created openslp tracking bugs for this issue:
Affects: fedora-all [bug 1572167]
---
Reproducible now. See: https://dumpco.re/blog/openslp-2.0.0-double-free
Re-opened this flaw to work on it a bit more.
[root@qeos-8 openslp-2.0.0]# slpd -d
*** Error in `slpd': double free or corruption (fasttop): 0x0000556d19e43ff0 ***
======= Backtrace: =========
/lib64/libc.so.6(+0x81489)[0x7fd1ae42d489]
slpd
http://support.lenovo.com/us/en/solutions/LEN-18247https://access.redhat.com/errata/RHSA-2018:2240https://access.redhat.com/errata/RHSA-2018:2308https://lists.debian.org/debian-lts-announce/2018/04/msg00029.htmlhttps://security.gentoo.org/glsa/202005-12https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/https://usn.ubuntu.com/3708-1/http://support.lenovo.com/us/en/solutions/LEN-18247https://access.redhat.com/errata/RHSA-2018:2240https://access.redhat.com/errata/RHSA-2018:2308https://lists.debian.org/debian-lts-announce/2018/04/msg00029.htmlhttps://security.gentoo.org/glsa/202005-12https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/https://usn.ubuntu.com/3708-1/
2018-04-23
Published