Описание
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
A flaw was found in FRRouting (FRR). A remote attacker can exploit an off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function by supplying a specially crafted FlowSpec component. This issue can lead to a Denial of Service (DoS).
Отчет
This vulnerability allows an unauthenticated remote attacker to cause a denial of service via a specially crafted FlowSpec component. Due to this reason, this issue has been rated with an important severity.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op ...
EPSS
7.5 High
CVSS3