opendaylight: odl-l2switch-switch feature does not handle closed-stream error
Published Apr 24, 2017
7.5
HIGHCVSS 3.0
EPSS 1.40%
Description
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 (Beryllium), 4.1 (Beryllium-SR1), 4.2 (Beryllium-SR2), and 4.4 (Beryllium-SR4) are affected by this flaw. Java version is openjdk version 1.8.0_91.
Affected products
No data.
- 3.3
- 4.0
No data.
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Not affected
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Not affected
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Because the odl-l2switch-switch feature has never been packaged for Red Hat OpenStack Platform, this flaw does not affect any RHOSP version.
References (7)
- https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf?sequence=1
- https://access.redhat.com/security/cve/CVE-2017-1000357 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1447185 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1519 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000357
- https://www.cve.org/CVERecord?id=CVE-2017-1000357
| Link | Providers | Tags |
|---|---|---|
| https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf?sequence=1 | ||
| https://access.redhat.com/security/cve/CVE-2017-1000357 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1447185 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1519 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000357 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000357 |
Change history (0)
No recorded changes yet.