Описание
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gobgp | fixed | 3.35.0-1 | package | |
| gobgp | no-dsa | bookworm | package | |
| gobgp | not-affected | bullseye | package |
Примечания
Fixed by: https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986 (v3.35.0)
Introduced by: https://github.com/osrg/gobgp/commit/c556ca4f8d6ed1d31a1a257af338abede79a321e (v3.11.0)
EPSS
Связанные уязвимости
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
GoBGP panics due to a zero value for softwareVersionLen
Уязвимость компонента pkg/packet/bgp/bgp.go реализации протокола BGP (Border Gateway Protocol) GoBGP, позволяющая нарушителю вызвать отказ в обслуживании
EPSS