Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-17205

EPSS 0.77% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-17205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows that were successfully applied from the same bundle. This is possible since OvS maintains list of old flows that were replaced by flows from the bundle. While reinserting old flows, OvS has an assertion failure due to a check on rule state != RULE_INITIALIZED. This would work for new flows, but for an old flow the rule state is RULE_REMOVED. The assertion failure causes an OvS crash.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Open vSwitch 输入验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Open vSwitch(OvS)是一款以开源技术作为基础(遵循Apache2.0许可)的多层虚拟交换机产品,它通过编程扩展支持大规模网络自动化,标准的管理接口和协议等。 OvS 2.7.x版本至2.7.6版本中的ofproto/ofproto.c文件的‘ofproto_rule_insert__’函数存在安全漏洞。攻击者可利用该漏洞造成OvS崩溃(断言失败)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2018-17205

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-17205

Please Login to view more intelligence information

Same Patch Batch · n/a · 2018-09-19 · 17 CVEs total

CVE-2018-17229Exiv2 缓冲区错误漏洞
CVE-2018-17230Exiv2 缓冲区错误漏洞
CVE-2018-17231Telegram Desktop 输入验证错误漏洞
CVE-2018-17228nmap4j 安全漏洞
CVE-2018-17208Belkin Intermational Linksys Velop 安全漏洞
CVE-2018-17204Open vSwitch 输入验证错误漏洞
CVE-2018-17206Open vSwitch 缓冲区错误漏洞
CVE-2018-17207Snap Creek Duplicator 安全漏洞
CVE-2018-16607Open-AudIT 跨站脚本漏洞
CVE-2018-16785DedeCMS 安全漏洞
CVE-2018-17183Artifex Ghostscript 输入验证错误漏洞
CVE-2018-11889Android WLAN 缓冲区错误漏洞
CVE-2018-11893Android WLAN 缓冲区错误漏洞
CVE-2018-5905Android Qualcomm Diag驱动程序权限许可和访问控制漏洞
CVE-2018-17182Linux kernel 安全漏洞
CVE-2018-17144Bitcoin Core和Bitcoin Knots 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2018-17205

No comments yet


Leave a comment