Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2010-3609 Details

Description

The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of service (infinite loop) via a packet with a "next extension offset" that references this extension or a previous extension. NOTE: some of these details are obtained from third party information.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://lists.vmware.com/pipermail/security-announce/2011/000126.html CVE
http://secunia.com/advisories/43601 CVEVendor Advisory
http://secunia.com/advisories/43742 CVEVendor Advisory
http://securityreason.com/securityalert/8127 CVE
http://securitytracker.com/id?1025168 CVE

see all 34 references

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions
openslp openslp
1.2.1

CPE

  • cpe:2.3:a:openslp:openslp:1.2.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
vmware esx
4.0
4.1

CPE

  • cpe:2.3:a:vmware:esx:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:esx:4.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
vmware esxi
4.0
4.1

CPE

  • cpe:2.3:a:vmware:esxi:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:esxi:4.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2010-3609
NVD Published Date:
Mar 11, 2011
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2010-3609 Details - Not Deferred