Vulnerability Bulletins

DSA-3533 openvswitch - security update

   
Affected software Debian
 
Kashyap Thimmaraju and Bhargava Shastry discovered a remotelytriggerable buffer overflow vulnerability in openvswitch, a productionquality, multilayer virtual switch implementation. Specially craftedMPLS packets could overflow the buffer reserved for MPLS labels in anOVS internal data structure. A remote attacker can take advantage ofthis flaw to cause a denial of service, or potentially, execution ofarbitrary code.

More info:

https://www.debian.org/security/2016/dsa-3533