Related Vulnerabilities: CVE-2023-29552  

DescriptionA flaw was found in OpenSLP. Service Location Protocol (SLP) is vulnerable to a reflective denial of service amplification attack via UDP. SLP allows an unauthenticated attacker to register new services without limits set by the SLP implementation. By using UDP and spoofing the source address, an attacker can request the service list, creating a Denial of Service on the spoofed address.A flaw was found in OpenSLP. Service Location Protocol (SLP) is vulnerable to a reflective denial of service amplification attack via UDP. SLP allows an unauthenticated attacker to register new services without limits set by the SLP implementation. By using UDP and spoofing the source address, an attacker can request the service list, creating a Denial of Service on the spoofed address.

Affected Packages and Issued Red Hat Security Errata

Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.