|
|
|
![]() |
Vulnerability Note VU#393783OpenSLP denial of service vulnerabilityOverviewOpenSLP contains a vulnerability in the handling of packets containing malformed extensions, which can result in a denial-of-service condition.I. DescriptionService Location Protocol is an IETF standards track protocol that provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in enterprise networks. The OpenSLP project is an effort to develop an open-source implementation of Service Location Protocol. When OpenSLP parses a SLP packet containing malformed extensions the extensions parser will enter an infinite loop causing a denial-of-service condition.If an attacker creates a packet containing a "next extension offset" pointing to itself or to a previous extension, the extension's parser will enter an infinite loop consuming 100% of the CPU.
Referenceshttp://openslp.svn.sourceforge.net/viewvc/openslp?view=revision&revision=1647 Thanks to Nicolas Gregoire of Agarri for reporting this vulnerability. This document was written by Michael Orlando.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||