Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41361

Опубликовано: 29 авг. 2023
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

A vulnerability was found in FRRouting stemming from a boundary error in bgpd/bgp_open.c. The issue arises because it fails to check for an excessively large length of the received software version (rcv). This flaw allows a remote attacker to overflow a buffer by sending specially crafted data to the application, leading to a denial of service condition.

Отчет

In Red Hat Enterprise Linux 8 and 9, the vulnerable code is not included. It was added much later during the development of the 9.x version of FRR in upstream. The highest version of FRR utilized in RHEL is 8.5. Consequently, none of the FRR versions shipped in RHEL are affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrNot affected
Red Hat Enterprise Linux 9frrNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2235844frr: does not check for an overly large length of the rcv software version

EPSS

Процентиль: 65%
0.00498
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

CVSS3: 9.8
nvd
почти 2 года назад

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

CVSS3: 9.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
почти 2 года назад

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not ...

CVSS3: 9.8
github
почти 2 года назад

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

EPSS

Процентиль: 65%
0.00498
Низкий

5.9 Medium

CVSS3