CVE-2017-14970 Information

Description

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1 there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report stating \it can only be triggered by an OpenFlow controller but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory such as by inserting flows into the flow table.\

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339085.html https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339086.html

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.9

Share on: