4
CVSSv2

CVE-2018-17206

Published: 19/09/2018 Updated: 04/03/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Open vSwitch (OvS) 2.7.x up to and including 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openvswitch openvswitch

redhat openstack 10

redhat openstack 13.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

debian debian linux 9.0

Vendor Advisories

Synopsis Moderate: openvswitch security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis Moderate: openvswitch security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Commo ...
Synopsis Moderate: openvswitch security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openvswitch is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Several security issues were fixed in Open vSwitch ...
An issue was discovered in Open vSwitch (OvS) 25x through 255, 26x through 263, 27x through 276, 28x through 284, and 29x through 292 where the decode_bundle function inside lib/ofp-actionsc is affected by a buffer over-read issue during BUNDLE action decoding A specially crafted flow update applied using the bundling feature ...