RHEL 7 : openvswitch (RHSA-2017:2418)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

An update for openvswitch is now available for Fast Datapath for Red
Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security
impact of Moderate. A Common Vulnerability Scoring System (CVSS) base
score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.

Open vSwitch provides standard network bridging functions and support
for the OpenFlow protocol for remote per-flow control of traffic.

The following packages have been upgraded to a later upstream version:
openvswitch (2.7.2). (BZ#1472854)

Security Fix(es) :

* An unsigned int wrap around leading to a buffer over-read was found
when parsing OFPT_QUEUE_GET_CONFIG_REPLY messages in Open vSwitch
(OvS). An attacker could use this flaw to cause a remote DoS.
(CVE-2017-9214)

* In Open vSwitch (OvS), while parsing an OpenFlow role status message
there is a call to the abort() function for undefined role status
reasons in the function `ofp_print_role_status_message` in
`lib/ofp-print.c` that may be leveraged toward a remote DoS attack by
a malicious switch. (CVE-2017-9263)

* A buffer over-read was found in the Open vSwitch (OvS) firewall
implementation. This flaw can be triggered by parsing a specially
crafted TCP, UDP, or IPv6 packet. A remote attack could use this flaw
to cause a Denial of Service (DoS). (CVE-2017-9264)

* A buffer over-read flaw was found in Open vSwitch (OvS) while
parsing the group mod OpenFlow messages sent from the controller. An
attacker could use this flaw to cause a Denial of Service (DoS).
(CVE-2017-9265)

See also :

http://rhn.redhat.com/errata/RHSA-2017-2418.html
https://www.redhat.com/security/data/cve/CVE-2017-9214.html
https://www.redhat.com/security/data/cve/CVE-2017-9263.html
https://www.redhat.com/security/data/cve/CVE-2017-9264.html
https://www.redhat.com/security/data/cve/CVE-2017-9265.html

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.5
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Red Hat Local Security Checks

Nessus Plugin ID: 102187 ()

Bugtraq ID:

CVE ID: CVE-2017-9214
CVE-2017-9263
CVE-2017-9264
CVE-2017-9265

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now