CVE-2017-17833

UnknownEPSS 3.89%

Last modified

CVE-2017-17833 is a vulnerability of currently unknown severity. OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.. EPSS estimates a 3.89% chance of exploitation in the next 30 days.

Description

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

Metrics

EPSS Probability
3.89%

88.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpenslpOpenslp1.0.2
OpenslpOpenslp1.1.0
DebianDebian Linux7.0
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Server Aus7.6
RedhatEnterprise Linux Server Eus7.5
RedhatEnterprise Linux Server Eus7.6
RedhatEnterprise Linux Server Tus7.6
RedhatEnterprise Linux Workstation6.0
RedhatEnterprise Linux Workstation7.0
LenovoThinkserver Rd350g FirmwareAll versions
LenovoThinkserver Rd350x FirmwareAll versions
LenovoThinkserver Rd450x FirmwareAll versions
LenovoThinksystem Hr630x FirmwareAll versions
LenovoThinksystem Hr650x FirmwareAll versions
LenovoThinksystem Sr630 FirmwareAll versions
LenovoFlex System Fc3171 8gb San Switch Firmware< 9.1.13.02.00
LenovoStorage N3310 Firmware< 4.53.351
LenovoStorage N4610 Firmware< 4.53.351
LenovoBm Nextscale Fan Power Controller< 24p-2.15
LenovoCmm< 1.8.0
LenovoFan Power Controller< 30r-1.13
LenovoImm1< 1.55
LenovoImm2< 4.70
LenovoXclarity Administrator< 1.4.0
LenovoThinkserver Rd340 Firmware< 50.00
LenovoThinkserver Rd350 Firmware< 4.53.351
LenovoThinkserver Rd440 Firmware<= 50.00
LenovoThinkserver Rd450 Firmware< 4.53.351
LenovoThinkserver Rd550 Firmware< 4.53.351
LenovoThinkserver Rd540 Firmware< 50.00
LenovoThinkserver Rd640 Firmware< 50.00
LenovoThinkserver Rd650 Firmware< 4.53.351
LenovoThinkserver Rq750 Firmware< 1.40
LenovoThinkserver Rs160 Firmware< 2.32
LenovoThinkserver Sd350 FirmwareAll versions
LenovoThinkserver Td340 Firmware< 46.00
LenovoThinkserver Td350 Firmware< 4.53.351
LenovoThinkserver Ts460 Firmware< 2.32

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-17833?
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
How severe is CVE-2017-17833?
Severity scoring for CVE-2017-17833 is pending analysis. The EPSS model estimates a 3.89% probability of exploitation in the next 30 days.
How do I fix CVE-2017-17833?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-17833?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST