CVE-2016-2074

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openvswitch:openvswitch:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:2.4.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2016-07-03 21:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-2074

Mitre link : CVE-2016-2074

CVE.ORG link : CVE-2016-2074


JSON object : View

Products Affected

openvswitch

  • openvswitch

redhat

  • openshift
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer