Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-41359

Опубликовано: 29 авг. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
frrnot-affectedpackage

Примечания

  • https://github.com/FRRouting/frr/pull/14232

  • Fixed by: https://github.com/FRRouting/frr/commit/f96201e104892e18493f24cf67bb713678e8237b

  • Backport for stable/8.5: https://github.com/FRRouting/frr/pull/14268

  • Fixed by: https://github.com/FRRouting/frr/commit/460ee930d6dbce6e96ecbfcd568a291f31bae24e

  • Introduced in: https://github.com/FRRouting/frr/commit/97a52c82a569f4a2ba792fbd734f5e635a057e6f (frr-8.5-rc)

EPSS

Процентиль: 48%
0.00245
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

CVSS3: 5.9
redhat
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

CVSS3: 9.1
nvd
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

CVSS3: 9.1
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 9.1
github
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

EPSS

Процентиль: 48%
0.00245
Низкий