4.3

CVE-2018-17204

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openvswitch ≫ Openvswitch Version >= 2.7.0 <= 2.7.6
Redhat ≫ Openstack Version 10
Redhat ≫ Openstack Version 13
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.91% 0.771
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://lists.debian.org/debian-lts-announce/2021/02/msg00032.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2018:3500
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0053
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0081
Third Party Advisory
https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde
Patch
Third Party Advisory
https://usn.ubuntu.com/3873-1/
Third Party Advisory