Back

CRITICAL

lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c

Published Jan 28, 2020

Description

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

Affected products

Remediation

Red Hat statement

The lldpd package as shipped with Red Hat Enterprise Linux 8 is not affected by this flaw because it has already received the patch. The flaw affects versions before 0.8.0 and the shipped version is 1.0.1+. In addition, Red Hat Virtualization 4.3 manager appliance is out of support scope and therefore no fix for it will be delivered.

Red Hat mitigation

When the lldpd source is compiled with source fortification enabled, the flaw becomes unexploitable and will just cause a crash.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 28, 2020
Updated Aug 6, 2024
Reserved Oct 28, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 15, 2015