Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh69-rw6w-x274

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

EPSS

Процентиль: 67%
0.0055
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

CVSS3: 7.5
debian
около 8 лет назад

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in ...

suse-cvrf
больше 1 года назад

Security update for frr

suse-cvrf
больше 1 года назад

Security update for quagga

suse-cvrf
больше 1 года назад

Security update for quagga

EPSS

Процентиль: 67%
0.0055
Низкий

7.5 High

CVSS3

Дефекты

CWE-200