CVE-2017-17833
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Affected (44)
Show all products
Openslp: Openslp · Debian: Debian Linux · Canonical: Ubuntu Linux · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Lenovo: Thinkserver Rd350g Firmware, Thinkserver Rd350x Firmware, Thinkserver Rd450x Firmware, Thinksystem Hr630x Firmware, Thinksystem Hr650x Firmware, Thinksystem Sr630 Firmware, Flex System Fc3171 8gb San Switch Firmware, Storage N3310 Firmware, Storage N4610 Firmware, Bm Nextscale Fan Power Controller, Cmm, Fan Power Controller, Imm1, Imm2, Xclarity Administrator, Thinkserver Rd340 Firmware, Thinkserver Rd350 Firmware, Thinkserver Rd440 Firmware, Thinkserver Rd450 Firmware, Thinkserver Rd550 Firmware, Thinkserver Rd540 Firmware, Thinkserver Rd640 Firmware, Thinkserver Rd650 Firmware, Thinkserver Rq750 Firmware, Thinkserver Rs160 Firmware, Thinkserver Sd350 Firmware, Thinkserver Td340 Firmware, Thinkserver Td350 Firmware, Thinkserver Ts460 Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 7.6 | |
| Version 7.5 | |
| Version 7.6 | |
| Version 6.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd350g | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd350x | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd450x | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinksystem Hr630x | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinksystem Hr650x | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinksystem Sr630 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.13.02.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Flex System Fc3171 8gb San Switch | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Storage N3310 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Storage N4610 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 24p-2.15 | |
| Before 1.8.0 | |
| Before 30r-1.13 | |
| Before 1.55 | |
| Before 4.70 | |
| Before 1.4.0 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 50.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd340 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd350 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 50.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd440 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd450 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd550 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 50.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd540 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 50.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd640 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd650 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.40 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rq750 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.32 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rs160 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Sd350 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 46.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Td340 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.53.351 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Td350 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.32 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Ts460 | All versions |
References (14)
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.