Описание
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
gobgp | fixed | 3.35.0-1 | package | |
gobgp | no-dsa | bookworm | package | |
gobgp | not-affected | bullseye | package |
Примечания
Fixed by: https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986 (v3.35.0)
Introduced by: https://github.com/osrg/gobgp/commit/c556ca4f8d6ed1d31a1a257af338abede79a321e (v3.11.0)
Связанные уязвимости
CVSS3: 8.6
ubuntu
5 месяцев назад
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
CVSS3: 8.6
nvd
5 месяцев назад
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
CVSS3: 8.6
github
5 месяцев назад
GoBGP panics due to a zero value for softwareVersionLen