MEDIUM
opendaylight: DOS by odl-mdsal-xsql feature
Published Apr 24, 2017
5.3
MEDIUMCVSS 3.0
EPSS 1.31%
Description
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
Affected products
No data.
OR
- 3.3
- 4.0
No data.
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Will not fix
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Not affected
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000359 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1447525 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000359
- https://www.cve.org/CVERecord?id=CVE-2017-1000359
| Link | Providers | Tags |
|---|---|---|
| https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-1000359 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1447525 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000359 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000359 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 24, 2017
Updated Sep 17, 2024
Reserved Apr 24, 2017
Link CVE-2017-1000359
CISA Vulnrichment
Updated n/a