Oval Definition:oval:com.redhat.rhsa:def:20194240
Revision Date:2019-12-16Version:637
Title:RHSA-2019:4240: openslp security update (Critical)
Description:OpenSLP is an open source implementation of the Service Location Protocol (SLP) which is an Internet Engineering Task Force (IETF) standards track protocol and provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in enterprise networks.

Security Fix(es):

  • openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution (CVE-2019-5544)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-5544
    RHSA-2019:4240
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • openslp is earlier than 1:2.0.0-8.el7_7
  • AND openslp is signed with Red Hat redhatrelease2 key
  • openslp-devel is earlier than 1:2.0.0-8.el7_7
  • AND openslp-devel is signed with Red Hat redhatrelease2 key
  • openslp-server is earlier than 1:2.0.0-8.el7_7
  • AND openslp-server is signed with Red Hat redhatrelease2 key
  • BACK