Buffer overflow in Open vSwitch - CVE-2016-2074

 

Buffer overflow in Open vSwitch - CVE-2016-2074

Published: April 2, 2018 / Updated: April 2, 2018


Vulnerability identifier: #VU11451
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2074
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in lib/flow.c in ovs-vswitchd due to boundary error. A remote attacker can send specially crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command, and execute arbitrary code.



Affected software

Open vSwitch
Debian Linux
Gentoo Linux
openvswitch (Alpine package)
openvswitch (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat OpenStack

How to mitigate CVE-2016-2074

Update to versions 2.3.3 or 2.4.1.

openvswitch (Alpine package) - update to 2.3.0-r7
openvswitch (Red Hat package) - update to 2.4.0-2.el7_2

External References

Related Security Bulletins