CVE-2016-2074 REJECTED

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.

EPSS 7.54% · 91.8th percentile

Risk Scores

EPSS Score
7.54%
91.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSopenvswitch0, 1.10.2-0ubuntu2, 2.0.0-0ubuntu3
Ubuntu:16.04:LTSopenvswitch0, 2.4.0-0ubuntu4, 2.4.0-0ubuntu5

Timeline

References

Open in Interactive Console →