Debian Openvswitch vulnerabilities
23 known vulnerabilities affecting debian/openvswitch.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH8MEDIUM4LOW5UNKNOWN1
Vulnerabilities
Page 2 of 2
CVE-2017-9263P4LOWCVSS 6.5fixed in openvswitch 2.8.1+dfsg1-2 (bookworm)2017
CVE-2017-9263 [MEDIUM] CVE-2017-9263: openvswitch - In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, ther...
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.
Scope: local
bookworm: resolved (fixed in 2.8.1+dfsg1-2)
bullseye: resolv
debian
CVE-2018-17204P4MEDIUMCVSS 4.3fixed in openvswitch 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-1 (bookworm)2018
CVE-2018-17204 [MEDIUM] CVE-2018-17204: openvswitch - An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting par...
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an
debian
CVE-2012-3449P4LOWCVSS 3.6fixed in openvswitch 1.4.2+git20120612-8 (bookworm)2012
CVE-2012-3449 [LOW] CVE-2012-3449: openvswitch - Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/...
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
Scope: local
bookworm: resolved (fixed in 1.4.2+git20120612-8)
bullseye: resolved (fixed in 1.4.2+git20120612-8)
forky: resolved (fixed in 1.
debian
← Previous2 / 2