Solution
Please Install the Updated Packages.
Insight
A vulnerability has been discovered and corrected in openslp:
The extension parser in slp_v2message.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (infinite loop) via a packet with a next extension offset that references this extension or a previous extension (CVE-2010-3609).
The updated packages have been patched to correct this issue.
Affected
openslp on Mandriva Linux 2011.0,
Mandriva Enterprise Server 5.2
Severity
Classification
-
CVE CVE-2010-3609 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities