OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
{
"binaries": [
{
"binary_version": "1.2.1-9ubuntu0.3+esm1",
"binary_name": "libslp-dev"
},
{
"binary_version": "1.2.1-9ubuntu0.3+esm1",
"binary_name": "libslp1"
},
{
"binary_version": "1.2.1-9ubuntu0.3+esm1",
"binary_name": "slpd"
},
{
"binary_version": "1.2.1-9ubuntu0.3+esm1",
"binary_name": "slptool"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "1.2.1-11ubuntu0.16.04.2",
"binary_name": "libslp-dev"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.2",
"binary_name": "libslp1"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.2",
"binary_name": "slpd"
},
{
"binary_version": "1.2.1-11ubuntu0.16.04.2",
"binary_name": "slptool"
}
],
"availability": "No subscription required"
}