Buffer overflow in Open vSwitch - CVE-2016-2074
Published: April 2, 2018 / Updated: April 2, 2018
Open vSwitch
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in lib/flow.c in ovs-vswitchd due to boundary error. A remote attacker can send specially crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command, and execute arbitrary code.