UBUNTU-CVE-2017-14970

Source
https://ubuntu.com/security/CVE-2017-14970
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-14970.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-14970
Related
Published
2017-10-02T01:29:00Z
Modified
2017-10-02T01:29:00Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

References

Affected packages

Ubuntu:Pro:16.04:LTS / openvswitch

Package

Name
openvswitch
Purl
pkg:deb/ubuntu/openvswitch?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.0-0ubuntu4
2.4.0-0ubuntu5
2.5.0~git20160129.46a88d9-0ubuntu1
2.5.0~git20160219.522aca6-0ubuntu1
2.5.0~git20160219.522aca6-0ubuntu2
2.5.0~git20160219.522aca6-0ubuntu3
2.5.0-0ubuntu1
2.5.2-0ubuntu0.16.04.1
2.5.2-0ubuntu0.16.04.2
2.5.2-0ubuntu0.16.04.3
2.5.4-0ubuntu0.16.04.1
2.5.5-0ubuntu0.16.04.1
2.5.5-0ubuntu0.16.04.2
2.5.9-0ubuntu0.16.04.2
2.5.9-0ubuntu0.16.04.3
2.5.9-0ubuntu0.16.04.3+esm1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:18.04:LTS / openvswitch

Package

Name
openvswitch
Purl
pkg:deb/ubuntu/openvswitch?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.0-0ubuntu1

Affected versions

2.*

2.8.0-0ubuntu2
2.8.1-0ubuntu2
2.8.1-0ubuntu3
2.9.0~git20180205.5a39582ca-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-common"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-dbg"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-doc"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-pki"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-switch"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-switch-dpdk"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-test"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-testcontroller"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "openvswitch-vtep"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "ovn-central"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "ovn-common"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "ovn-controller-vtep"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "ovn-docker"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "ovn-host"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "python-openvswitch"
        },
        {
            "binary_version": "2.9.0-0ubuntu1",
            "binary_name": "python3-openvswitch"
        }
    ]
}