GPU VulnDB

Database/Control plane, storage & DevOps

lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addresses

CVE-2015-8011Control plane, storage & DevOpscurated

Impact

Buffer overflow in lldpd's LLDP decoder via large management addresses and TLV boundaries, allowing daemon crash and possibly code execution. Old, but included because lldpd is one of those daemons that ships inside embedded switch and appliance images and stays frozen at whatever version the vendor picked years ago — the CVE date tells you nothing about whether your fabric is running it.

Who can reach it

Unauthenticated, adjacent — a crafted LLDP frame.

What to do

Upgrade lldpd past 0.8.0 and restart. On embedded NOSes and appliances, check the shipped lldpd version explicitly rather than assuming a modern image implies a modern lldpd. Companion crash issue: CVE-2015-8012.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.