Описание
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps/bionic | released | 1.29-1ubuntu0.1+esm2 |
| esm-apps/focal | released | 2.12.0-1ubuntu0.1~esm3 |
| esm-apps/jammy | released | 2.25.0-3ubuntu0.1+esm4 |
| esm-apps/noble | released | 3.23.0-1ubuntu0.3+esm4 |
| esm-apps/resolute | released | 3.36.0-2ubuntu0.1~esm1 |
| jammy | needed | |
| noble | needed | |
| questing | ignored | end of life, was needed |
| resolute | needed |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by ...
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3