Database/Control plane, storage & DevOps
lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addresses
Impact
Buffer overflow in lldpd's LLDP decoder via large management addresses and TLV boundaries, allowing daemon crash and possibly code execution. Old, but included because lldpd is one of those daemons that ships inside embedded switch and appliance images and stays frozen at whatever version the vendor picked years ago — the CVE date tells you nothing about whether your fabric is running it.
Who can reach it
Unauthenticated, adjacent — a crafted LLDP frame.
What to do
Upgrade lldpd past 0.8.0 and restart. On embedded NOSes and appliances, check the shipped lldpd version explicitly rather than assuming a modern image implies a modern lldpd. Companion crash issue: CVE-2015-8012.
References
Related entries
- Lantronix xPrintServer: The device ships with a hardcoded root account baked into every unit of a given firmware lineCVE-2016-4325 · Lantronix xPrintServerCritical
- HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoSCVE-2016-4375 · HPE iLO3 / iLO4Critical
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCVE-2017-5689 · Intel Active Management Technology / Standard ManageabilityCritical
- HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CVE-2017-8979 · HPE iLO2Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.