Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openslp | Openslp | 1.2.1 (including) | 1.2.1 (including) |
| Openslp-dfsg | Ubuntu | devel | * |
| Openslp-dfsg | Ubuntu | esm-infra-legacy/trusty | * |
| Openslp-dfsg | Ubuntu | precise | * |
| Openslp-dfsg | Ubuntu | trusty | * |
| Openslp-dfsg | Ubuntu | trusty/esm | * |
| Openslp-dfsg | Ubuntu | upstream | * |
| Openslp-dfsg | Ubuntu | vivid | * |