CVE-2017-14970
Last modified
CVE-2017-14970 is a vulnerability of currently unknown severity. In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table.". EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openvswitch | Openvswitch | <= 2.8.0 |
References
- https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339085.htmlMailing List, Patch, Vendor Advisory
- https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339086.htmlMailing List, Patch, Vendor Advisory
- https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339085.htmlMailing List, Patch, Vendor Advisory
- https://mail.openvswitch.org/pipermail/ovs-dev/2017-September/339086.htmlMailing List, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14970?
How severe is CVE-2017-14970?
How do I fix CVE-2017-14970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14965In IKARUS anti.virus before 2.16.18, the ntguard.sys driver …
- CVE-2017-14966In IKARUS anti.virus before 2.16.18, the ntguard.sys driver …
- CVE-2017-14967In IKARUS anti.virus before 2.16.18, the ntguard.sys driver …
- CVE-2017-14968In IKARUS anti.virus before 2.16.18, the ntguard.sys driver …
- CVE-2017-14969In IKARUS anti.virus before 2.16.18, the ntguard.sys driver …
- CVE-2017-1497IBM Sterling File Gateway 2.2 could allow an unauthorized us…
- CVE-2017-14971Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential…
- CVE-2017-14972InFocus Mondopad 2.2.08 is vulnerable to authentication bypa…
- CVE-2017-14973IDenticard Two-Reader Controller Configuration Manager 1.18.…
- CVE-2017-14974The *_get_synthetic_symtab functions in the Binary File Desc…
- CVE-2017-14975The FoFiType1C::convertToType0 function in FoFiType1C.cc in …
- CVE-2017-14976The FoFiType1C::convertToType0 function in FoFiType1C.cc in …
Are you affected by CVE-2017-14970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
