Open vSwitch: Remote execution of arbitrary code A buffer overflow in Open vSwitch might allow remote attackers to execute arbitrary code. openvswitch 2017-01-01 2017-01-01 577568 remote 2.5.0 2.5.0

Open vSwitch is a production quality multilayer virtual switch.

A buffer overflow was discovered in lib/flow.c in ovs-vswitchd.

A remote attacker, using a specially crafted MPLS packet, could execute arbitrary code.

There is no known workaround at this time.

All Open vSwitch users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/openvswitch-2.5.0"
CVE-2016-2074 b-man b-man