CVE-2015-8011
28.01.2020, 19:15
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
| Vendor | Product | Version |
|---|---|---|
| lldpd_project | lldpd | 0.5.6 ≤ 𝑥 < 0.8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| lldpd |
| ||||||||||||||||
| openvswitch |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| lldpd |
| ||||||||||||||||||||||||||
| openvswitch |
|
References