Candidate: CVE-2016-2074 CRD: 2016-03-28 PublicDate: 2016-07-03 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2074 http://openvswitch.org/pipermail/announce/2016-March/000082.html Description: Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command. Ubuntu-Description: Notes: mdeslaur> in 2.4, is a DoS only, and only if debug logging is enabled Bugs: Priority: low Discovered-by: Kashyap Thimmaraju and Bhargava Shastry Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_openvswitch: upstream_openvswitch: released (2.5) precise_openvswitch: ignored (reached end-of-life) precise/esm_openvswitch: DNE (precise was needed [1.4.6-0ubuntu1.12.04.5]) trusty_openvswitch: not-affected (2.0.2-0ubuntu0.14.04.3) trusty/esm_openvswitch: DNE (trusty was not-affected [2.0.2-0ubuntu0.14.04.3]) vivid/stable-phone-overlay_openvswitch: DNE vivid/ubuntu-core_openvswitch: DNE wily_openvswitch: ignored (reached end-of-life) xenial_openvswitch: not-affected (2.5.0-0ubuntu1) esm-infra/xenial_openvswitch: not-affected (2.5.0-0ubuntu1) yakkety_openvswitch: not-affected (2.5.0-0ubuntu1) zesty_openvswitch: not-affected (2.5.0-0ubuntu1) devel_openvswitch: not-affected (2.5.0-0ubuntu1)