Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:MISC:OPENSLP-PROJECT-BO

Severity

Major

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

OpenSLP Project and VMWare OpenSLP Heap Buffer Overflow

Release Date

2020/01/01

Update Number

3240

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: OpenSLP Project and VMWare OpenSLP Heap Buffer Overflow


This signature detects attempts to exploit a known vulnerability against OpenSLP. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Affected Products

  • Openslp openslp 1.2.1
  • Openslp openslp 2.0.0
  • Redhat enterprise_linux_desktop 7.0
  • Redhat enterprise_linux_server 7.0
  • Redhat enterprise_linux_server_aus 7.7
  • Redhat enterprise_linux_server_eus 7.7
  • Redhat enterprise_linux_server_tus 7.7
  • Redhat enterprise_linux_workstation 7.0
  • Vmware esxi 6.0
  • Vmware esxi 6.5
  • Vmware esxi 6.7
  • Vmware horizon_daas 8.0.0
  • Vmware horizon_daas 8.0.1

References

  • CVE: CVE-2019-5544

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out