Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-37035

Опубликовано: 03 авг. 2022
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

A flaw was found in bgpd in FRRouting (FRR). There is a possible use-after-free issue due to a race condition in bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c. This issue can lead to remote code execution or information disclosure by sending crafted BGP packets.

Отчет

User interaction is not needed for exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrNot affected
Red Hat Enterprise Linux 9frrNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2118615frr: use-after-free bug due to race conditions in two threads

EPSS

Процентиль: 86%
0.03024
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 3 года назад

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

CVSS3: 8.1
nvd
почти 3 года назад

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

CVSS3: 8.1
debian
почти 3 года назад

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_ ...

CVSS3: 8.1
github
почти 3 года назад

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

CVSS3: 4.3
fstec
почти 3 года назад

Уязвимость функций bgp_notify_send_with_data() и bgp_process_packet() (bgp_packet.c) программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 86%
0.03024
Низкий

8.1 High

CVSS3