Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 20 Openslp: 2015-7561 Moderate: DoS Vulnerability Advisory

fedora
Calendar Grey May 27, 2015
Dist Fedora Esm H88
Ubuntu 22.04 has rolled out a critical security patch for openslp, targeting a vulnerability that could lead to service interruptions for its users.
openslp: denial of service vulnerability (CVE-2010-3609)

Summary

Service Location Protocol is an IETF standards track protocol that

provides a framework to allow networking applications to discover the

existence, location, and configuration of networked services in

enterprise networks.

OpenSLP is an open source implementation of the SLPv2 protocol as defined

by RFC 2608 and RFC 2614.

Update Information:

openslp: denial of service vulnerability (CVE-2010-3609)

Change Log

* Mon May 11 2015 Rex Dieter 1.2.1-22 - openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS (CVE-2012-4428, #857242) * Mon May 4 2015 Rex Dieter 1.2.1-21 - openslp: denial of service vulnerability (CVE-2010-3609, #684294)

References


[ 1 ] Bug #684294 - CVE-2010-3609 openslp: denial of service vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=684294 [ 2 ] Bug #857242 - CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS https://bugzilla.redhat.com/show_bug.cgi?id=857242

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update openslp' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: openslp
Product: Fedora 20
Version: 1.2.1
Release: 22.fc20
Summary: Open implementation of Service Location Protocol V2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here