CVE-2016-7567 describes a critical buffer overflow vulnerability in the SLPFoldWhiteSpace function within OpenSLP 2.0, allowing remote attackers to achieve significant impact through crafted strings. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without authentication or user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry exists (EDB-45804) detailing multiple vulnerabilities in OpenSLP 2.0.0, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:openslp:openslp:2.0.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2016-7567
Jun 11, 2024Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.
Jan 10, 2017openslp: memory corruption due to possible overflow in SLPFoldWhiteSpace in common/slp_compare.c
Sep 27, 2016