Name | CVE-2015-5177 |
Description | Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-304-1, DSA-3353-1 |
Debian Bugs | 795429 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
openslp-dfsg | source | squeeze | 1.2.1-7.8+deb6u1 | DLA-304-1 | ||
openslp-dfsg | source | wheezy | 1.2.1-9+deb7u1 | DSA-3353-1 | ||
openslp-dfsg | source | jessie | 1.2.1-10+deb8u1 | DSA-3353-1 | ||
openslp-dfsg | source | (unstable) | 1.2.1-11 | 795429 |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5177