CVE-2017-9264
published 2017-05-29CVE-2017-9264: In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets…
PriorityP343critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.42%
82.3th percentile
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 2.8.1+dfsg1-2 (bookworm) | openvswitch 2.8.1+dfsg1-2 (bookworm) |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.8.1+dfsg1-2 | 2.8.1+dfsg1-2 |
| openvswitch | openvswitch | >= 0 < 2.5.2-0ubuntu0.16.04.2 | 2.5.2-0ubuntu0.16.04.2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 9.8
CVE-2017-9214 [CRITICAL] Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
Bhargava Shastry discovered that Open vSwitch incorrectly handled certain
OFP messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9214)
It was discovered that Open vSwitch incorrectly handled certain OpenFlow
role messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9263)
It was discovered that Open vSwitch incorrectly handled certain malformed
packets. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 17.04. (CVE-2017-9264)
It was dis
Red Hat
openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
vendor_redhat·2017-03-03·CVSS 9.8
CVE-2017-9264 [CRITICAL] CWE-122 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
A buffer over-read was found in the Open vSwitch (OvS) firewall implementation. This flaw can be triggered by parsing a specially crafted TCP, UDP, or IPv6 packet. A remote attack could use this flaw to cause a Denial of Service (DoS).
Package: openvswitch (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openvswitch (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: openvswitch (Red Ha
Debian
CVE-2017-9264: openvswitch - In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, t...
vendor_debian·2017·CVSS 9.8
CVE-2017-9264 [CRITICAL] CVE-2017-9264: openvswitch - In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, t...
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
Scope: local
bookworm: resolved (fixed in 2.8.1+dfsg1-2)
bullseye: resolved (fixed in 2.8.1+dfsg1-2)
forky: resolved (fixed in 2.8.1+dfsg1-2)
sid: resolved (fixed in 2.8.1+dfsg1-2)
trixie: resolved (fixed in 2.8.1+dfsg1-2)
GHSA
GHSA-r4pw-w7qg-248f: In lib/conntrack
ghsa_unreviewed·2022-05-13
CVE-2017-9264 [CRITICAL] CWE-125 GHSA-r4pw-w7qg-248f: In lib/conntrack
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
OSV
openvswitch vulnerabilities
osv·2017-10-11·CVSS 9.8
CVE-2017-9214 [CRITICAL] openvswitch vulnerabilities
openvswitch vulnerabilities
Bhargava Shastry discovered that Open vSwitch incorrectly handled certain
OFP messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9214)
It was discovered that Open vSwitch incorrectly handled certain OpenFlow
role messages. A remote attacker could possibly use this issue to cause
Open vSwitch to crash, resulting in a denial of service. (CVE-2017-9263)
It was discovered that Open vSwitch incorrectly handled certain malformed
packets. A remote attacker could possibly use this issue to cause Open
vSwitch to crash, resulting in a denial of service. This issue only
affected Ubuntu 17.04. (CVE-2017-9264)
It was discovered that Open vSwitch incorrectly handled group mod OpenFlow
messa
OSV
CVE-2017-9264: In lib/conntrack
osv·2017-05-29·CVSS 9.8
CVE-2017-9264 [CRITICAL] CVE-2017-9264: In lib/conntrack
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-16898 ming: Buffer overflow in the printMP3Headers function
bugzilla·2017-11-21·CVSS 5.5
CVE-2017-16898 [MEDIUM] CVE-2017-16898 ming: Buffer overflow in the printMP3Headers function
CVE-2017-16898 ming: Buffer overflow in the printMP3Headers function
The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.
Upstream issue:
https://github.com/libming/libming/issues/75
Discussion:
Created ming tracking bugs for this issue:
Affects: fedora-all [bug 1476729]
Bugzilla
CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
bugzilla·2017-05-31·CVSS 9.8
CVE-2017-9264 [CRITICAL] CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
In lib/conntrack.c in the firewall implementation in Open vSwitch, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 10.0 (Newton)
Via RH
Bugzilla
CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
bugzilla·2017-05-30·CVSS 8.8
CVE-2016-10377 [HIGH] CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
CVE-2016-10377 CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 openvswitch: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
arXiv
Static Exploration of Taint-Style Vulnerabilities Found by Fuzzing
arxiv_fulltext·2017-06-01
Static Exploration of Taint-Style Vulnerabilities Found by Fuzzing
Static Exploration of Taint-Style Vulnerabilities Found by Fuzzing
[1]Bhargava Shastry
[2]Federico Maggi
[3]Fabian Yamaguchi
[3]Konrad Rieck
[1]Jean-Pierre Seifert
[1]Technische Universit\"at Berlin
[2]Trend Micro Inc.
[3]Technische Universit\"at Braunschweig
and
## Abstract
Taint-style vulnerabilities comprise a majority of fuzzer discovered program faults.
These vulnerabilities usually manifest as memory access violations caused by tainted program input.
Although fuzzers have helped uncover a majority of taint-style vulnerabilities in software to date, they are limited by (i) extent of test coverage; and (ii) the availability of fuzzable test cases.
Therefore, fuzzing alone cannot provide a high assurance that all taint-style vulnerabilities have been uncovered.
In this paper, we us
https://access.redhat.com/errata/RHSA-2017:2418https://access.redhat.com/errata/RHSA-2017:2648https://access.redhat.com/errata/RHSA-2017:2727https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.htmlhttps://access.redhat.com/errata/RHSA-2017:2418https://access.redhat.com/errata/RHSA-2017:2648https://access.redhat.com/errata/RHSA-2017:2727https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html
2017-05-29
Published