| Vulnerability Name: | CVE-2015-8011 (CCN-107742) | ||||||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2015-10-29 | ||||||||||||||||||||||||||||||||||||||||||||
| Published: | 2015-10-29 | ||||||||||||||||||||||||||||||||||||||||||||
| Updated: | 2021-08-02 | ||||||||||||||||||||||||||||||||||||||||||||
| Summary: | Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries. | ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-120 | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-8011 Source: CCN Type: oss-sec Mailing List, Thu, 29 Oct 2015 20:28:22 -0400 (EDT) Re: CVE request: lldpd crash in lldp_decode due large management address Source: CCN Type: oss-sec Mailing List, Fri, 16 Oct 2015 08:05:57 +0200 CVE request: lldpd crash in lldp_decode due large management address Source: MISC Type: Mailing List, Patch, Third Party Advisory http://www.openwall.com/lists/oss-security/2015/10/16/2 Source: MISC Type: Mailing List, Patch, Third Party Advisory http://www.openwall.com/lists/oss-security/2015/10/30/2 Source: CCN Type: BID-77114 lldp 'protocols/lldp.c' Buffer Overflow Vulnerability Source: CONFIRM Type: UNKNOWN https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf Source: XF Type: UNKNOWN lldpd-cve20158011-dos(107742) Source: CCN Type: lldpd GIT repository lldpd Source: MISC Type: Patch, Third Party Advisory https://github.com/vincentbernat/lldpd/commit/dd4f16e7e816f2165fba76e3d162cd8d2978dcb2 Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210219 [SECURITY] [DLA 2571-1] openvswitch security update Source: FEDORA Type: Third Party Advisory FEDORA-2021-fba11d37ee Source: DEBIAN Type: Third Party Advisory DSA-4836 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8011 | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||||||