Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 25 OpenSLP Security Patch: Memory Overflow Risk Mitigation

fedora
Calendar Grey March 22, 2017
Dist Fedora Esm H88
Update for Fedora 25 resolves potential buffer overflow in OpenSLP protocol, tackling security vulnerabilities.
Fix possible overflow in SLPFoldWhiteSpace, CVE-2016-7567

Summary

Service Location Protocol is an IETF standards track protocol that

provides a framework to allow networking applications to discover the

existence, location, and configuration of networked services in

enterprise networks.

OpenSLP is an open source implementation of the SLPv2 protocol as defined

by RFC 2608 and RFC 2614.

Update Information:

Fix possible overflow in SLPFoldWhiteSpace, CVE-2016-7567

Change Log

References


[ 1 ] Bug #1379988 - CVE-2016-7567 openslp: memory corruption due to possible overflow in SLPFoldWhiteSpace in common/slp_compare.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1379988

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade openslp' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: openslp
Product: Fedora 25
Version: 2.0.0
Release: 10.fc25
Summary: Open implementation of Service Location Protocol V2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here