CVE-2015-5177: Debian Linux

High severity, CVSS 7.5. EPSS: 6.3% chance of exploitation in the next 30 days.

Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Openslp Openslp: version 1.2.1 only

Published 2017-10-22. Last modified 2026-06-17.