Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-26126

Опубликовано: 05 фев. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

frrouting is vulnerable to a flaw that can cause stack overflow due to processing binary data as simple string data. Since c string data is not being processed when processing packets , correct binary aware functions should be used. There is high impact to availability due to the fact that the process up-time can be made unreliable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrWill not fix
Red Hat Enterprise Linux 9frrWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2058640frrouting: Misusing strdup leads to stack overflow in isis_nb_notifications.c

EPSS

Процентиль: 62%
0.01085
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

CVSS3: 7.8
nvd
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

CVSS3: 7.8
debian
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due t ...

CVSS3: 7.8
github
больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

suse-cvrf
больше 4 лет назад

Security update for frr

EPSS

Процентиль: 62%
0.01085
Низкий

7.8 High

CVSS3