openslp-2.0.0-7.el7

エラータID: AXSA:2018-3271:01

Release date: 
Wednesday, August 1, 2018 - 09:24
Subject: 
openslp-2.0.0-7.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

OpenSLP is an open source implementation of the Service Location Protocol (SLP) which is an Internet Engineering Task Force (IETF) standards track protocol and provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in enterprise networks.

Security Fix(es):

* openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution (CVE-2017-17833)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2017-17833
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. openslp-2.0.0-7.el7.src.rpm
    MD5: 513b1bf86a73c2c7b81a194d8196c8e7
    SHA-256: 73d12d711477d6a2212485bc001831dfd4093140a3e4866faaaa71b5434e50a5
    Size: 5.13 MB

Asianux Server 7 for x86_64
  1. openslp-2.0.0-7.el7.x86_64.rpm
    MD5: b0c51e0571dbe3cd1acf60387c8e5389
    SHA-256: a40bf6a73f7b911125803f5edd3d764e08b0dca6df4ccc2d4d06977b71a0f63f
    Size: 324.63 kB
  2. openslp-server-2.0.0-7.el7.x86_64.rpm
    MD5: 636294e7b7ab7ac0de7892aa3d9e7409
    SHA-256: 2e514c573ee9eff6a9c092d35d6db25c35ff937316d9e9888824f8896ba57f4c
    Size: 73.99 kB
  3. openslp-2.0.0-7.el7.i686.rpm
    MD5: 1a7ae18e848adcfc0bcb081a89930127
    SHA-256: a2ac1a3c70fe61b31a06c5e2a5051a5955d84f2f8d525dba8eb1a4e2a077dd6d
    Size: 325.48 kB