Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openslp | Openslp | 1.2.1 (including) | 1.2.1 (including) |
Openslp-dfsg | Ubuntu | devel | * |
Openslp-dfsg | Ubuntu | precise | * |
Openslp-dfsg | Ubuntu | trusty | * |
Openslp-dfsg | Ubuntu | upstream | * |
Openslp-dfsg | Ubuntu | vivid | * |