Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26129

Опубликовано: 03 мар. 2022
Источник: debian

Описание

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
frrfixed8.4.1-1package

Примечания

  • https://github.com/FRRouting/frr/issues/10503

  • Fixed by: https://github.com/FRRouting/frr/issues/10504 (together with CVE-2022-26128)

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

CVSS3: 8.1
redhat
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

CVSS3: 7.8
nvd
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

CVSS3: 7.8
github
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость функций parse_hello_subtlv(), parse_ihu_subtlv() и parse_update_subtl() программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, позволяющая нарушителю выполнить произвольный код