Back
CVE-2017-17833
CRITICAL
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Published: Apr 23, 2018
Modified: Jun 17, 2026
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (44)
| Vendor | Product | Version |
|---|---|---|
| openslp | openslp | 1.0.2 |
| openslp | openslp | 1.1.0 |
| debian | debian_linux | 7.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| lenovo | thinkserver_rd350g_firmware | - |
| lenovo | thinkserver_rd350x_firmware | - |
| lenovo | thinkserver_rd450x_firmware | - |
| lenovo | thinksystem_hr630x_firmware | - |
| lenovo | thinksystem_hr650x_firmware | - |
…and 24 more
GitHub Security Advisory GHSA-r3mh-hjcg-756h
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue...
References (14)
- http://support.lenovo.com/us/en/solutions/LEN-18247 Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2240 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2308 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00029.html Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-12
- https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/ Patch, Third Party Advisory
- https://usn.ubuntu.com/3708-1/ Third Party Advisory
- http://support.lenovo.com/us/en/solutions/LEN-18247 Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2240 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2308 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00029.html Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-12
- https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/ Patch, Third Party Advisory
- https://usn.ubuntu.com/3708-1/ Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
3.89%
Top 11% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub