Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
slpd-lite unauthenticated memory corruption
Vulnerability Description
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
slpd-lite 安全漏洞
Vulnerability Description
slpd-lite是OpenBMC开源的一个简单 SLP 应答器。 slpd-lite存在安全漏洞,该漏洞源于包含一个缓冲区溢出问题。
CVSS Information
N/A
Vulnerability Type
N/A