Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15865

Опубликовано: 08 нояб. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*
Версия до 2.0.2 (исключая)
cpe:2.3:a:frrouting:frrouting:3.0:*:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc0:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0.1:*:*:*:*:*:*:*
cpe:2.3:o:cumulusnetworks:cumulus_linux:*:*:*:*:*:*:*:*
Версия до 3.4.3 (исключая)

EPSS

Процентиль: 67%
0.0055
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
debian
около 8 лет назад

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in ...

suse-cvrf
больше 1 года назад

Security update for frr

CVSS3: 7.5
github
больше 3 лет назад

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

suse-cvrf
больше 1 года назад

Security update for quagga

suse-cvrf
больше 1 года назад

Security update for quagga

EPSS

Процентиль: 67%
0.0055
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200