Back

CVE-2017-17833

CRITICAL

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

Published: Apr 23, 2018 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (44)

Vendor Product Version
openslp openslp 1.0.2
openslp openslp 1.1.0
debian debian_linux 7.0
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_server_eus 7.6
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_workstation 7.0
lenovo thinkserver_rd350g_firmware -
lenovo thinkserver_rd350x_firmware -
lenovo thinkserver_rd450x_firmware -
lenovo thinksystem_hr630x_firmware -
lenovo thinksystem_hr650x_firmware -

…and 24 more

GitHub Security Advisory GHSA-r3mh-hjcg-756h

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.89%

Top 11% most likely to be exploited

Threat Score 40.4 / 100

Data Sources

NVD EPSS GitHub