Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41360

Опубликовано: 29 авг. 2023
Источник: redhat
CVSS3: 4.8

Описание

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

An out-of-bounds read flaw was found in FRRouting in bgpd/bgp_packet.c, resulting from a boundary condition. This flaw allows a remote attacker, through specially crafted input, to read the initial byte of the ORF header in an ahead-of-stream scenario. This attacker can gain information and potentially launch further attacks against the affected system.

Отчет

In Red Hat Enterprise Linux 8, the vulnerable code is not included. It was added in FRR-8.4 in upstream. The highest version of FRR utilized in RHEL-8 is 7.5. Hence, versions of FRR shipped with RHEL-8 are not affected by this vulnerability. Red Hat Product Security rated this vulnerability as a LOW security impact because it only exposes the initial byte of the ORF header in an ahead-of-stream situation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrNot affected
Red Hat Enterprise Linux 9frrFixedRHSA-2024:215630.04.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2235842frr: ahead-of-stream read of ORF header

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

CVSS3: 9.1
nvd
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

CVSS3: 9.1
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 9.1
debian
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet. ...

CVSS3: 9.1
github
почти 2 года назад

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

4.8 Medium

CVSS3