OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
{
"binaries": [
{
"binary_version": "1.2.1-9ubuntu0.3",
"binary_name": "libslp-dev"
},
{
"binary_version": "1.2.1-9ubuntu0.3",
"binary_name": "libslp1"
},
{
"binary_version": "1.2.1-9ubuntu0.3",
"binary_name": "slpd"
},
{
"binary_version": "1.2.1-9ubuntu0.3",
"binary_name": "slptool"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1.2.1-11ubuntu0.16.04.1",
"binary_name": "libslp-dev"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.1",
"binary_name": "libslp1"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.1",
"binary_name": "slpd"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.1",
"binary_name": "slptool"
}
],
"availability": "No subscription required"
}