CVE Database
/

CVE-2010-3609

Back to search

CVE-2010-3609

Published: Mar 11, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of service (infinite loop) via a packet with a "next extension offset" that references this extension or a previous extension. NOTE: some of these details are obtained from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#393783
third-party-advisory
x_refsource_CERT-VN
43742
third-party-advisory
x_refsource_SECUNIA
71019
vdb-entry
x_refsource_OSVDB
ADV-2011-0606
vdb-entry
x_refsource_VUPEN
MDVSA-2013:111
vendor-advisory
x_refsource_MANDRIVA
8127
third-party-advisory
x_refsource_SREASON
1025168
vdb-entry
x_refsource_SECTRACK
GLSA-201707-05
vendor-advisory
x_refsource_GENTOO
vmware-esxserver-slpd-dos(65931)
vdb-entry
x_refsource_XF
ADV-2011-0729
vdb-entry
x_refsource_VUPEN
MDVSA-2012:141
vendor-advisory
x_refsource_MANDRIVA
46772
vdb-entry
x_refsource_BID
43601
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now