CVE-2017-17833

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openslp:openslp:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:openslp:openslp:1.1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd350g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd350g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd350x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd350x:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd450x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd450x:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:lenovo:thinksystem_hr630x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_hr630x:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:lenovo:thinksystem_hr650x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_hr650x:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:lenovo:thinksystem_sr630_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr630:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:lenovo:flex_system_fc3171_8gb_san_switch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_fc3171_8gb_san_switch:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:lenovo:storage_n3310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:storage_n3310:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:lenovo:storage_n4610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:storage_n4610:-:*:*:*:*:*:*:*

Configuration 14 (hide)

OR cpe:2.3:a:lenovo:bm_nextscale_fan_power_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:cmm:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:fan_power_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:imm1:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:imm2:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd340:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd350_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd350:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd440:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd450_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd450:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd550_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd550:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd540:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd640:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd650:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rq750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rq750:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rs160_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rs160:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_sd350_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_sd350:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_td340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_td340:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_td350_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_td350:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_ts460_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_ts460:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-23 18:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-17833

Mitre link : CVE-2017-17833

CVE.ORG link : CVE-2017-17833


JSON object : View

Products Affected

lenovo

  • bm_nextscale_fan_power_controller
  • thinkserver_td340_firmware
  • thinkserver_ts460_firmware
  • thinksystem_hr650x
  • xclarity_administrator
  • thinkserver_rd540_firmware
  • thinkserver_rd340_firmware
  • thinkserver_rd350g
  • thinkserver_rd440
  • thinkserver_rd540
  • thinkserver_rd640
  • thinkserver_rd350g_firmware
  • thinkserver_rd450x_firmware
  • thinksystem_hr650x_firmware
  • thinkserver_rs160
  • thinkserver_rs160_firmware
  • thinkserver_td350
  • thinkserver_rd350x
  • storage_n4610_firmware
  • thinkserver_rd650
  • storage_n3310_firmware
  • thinkserver_rd340
  • thinksystem_hr630x_firmware
  • thinksystem_sr630_firmware
  • flex_system_fc3171_8gb_san_switch
  • fan_power_controller
  • thinkserver_rq750
  • thinkserver_sd350_firmware
  • thinksystem_hr630x
  • thinkserver_rd550
  • imm2
  • thinkserver_rd450
  • thinkserver_rd640_firmware
  • thinkserver_rd650_firmware
  • thinkserver_rd350x_firmware
  • flex_system_fc3171_8gb_san_switch_firmware
  • thinkserver_sd350
  • thinkserver_rd550_firmware
  • thinkserver_td350_firmware
  • thinkserver_ts460
  • thinksystem_sr630
  • thinkserver_rd350
  • imm1
  • thinkserver_rd440_firmware
  • thinkserver_rd350_firmware
  • storage_n3310
  • cmm
  • storage_n4610
  • thinkserver_rq750_firmware
  • thinkserver_td340
  • thinkserver_rd450x
  • thinkserver_rd450_firmware

redhat

  • enterprise_linux_server_eus
  • enterprise_linux_server
  • enterprise_linux_workstation
  • enterprise_linux_server_tus
  • enterprise_linux_desktop
  • enterprise_linux_server_aus

debian

  • debian_linux

canonical

  • ubuntu_linux

openslp

  • openslp
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer