Database/Control plane, storage & DevOps
lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addresses
Impact
Buffer overflow in lldpd's LLDP decoder via large management addresses and TLV boundaries, allowing daemon crash and possibly code execution. Old, but included because lldpd is one of those daemons that ships inside embedded switch and appliance images and stays frozen at whatever version the vendor picked years ago — the CVE date tells you nothing about whether your fabric is running it.
Who can reach it
Unauthenticated, adjacent — a crafted LLDP frame.
What to do
Upgrade lldpd past 0.8.0 and restart. On embedded NOSes and appliances, check the shipped lldpd version explicitly rather than assuming a modern image implies a modern lldpd. Companion crash issue: CVE-2015-8012.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.