FRRouting 8.5.1

CPE Details

FRRouting 8.5.1
8.5.1
2023-05-16
15h33 +00:00
2023-05-22
11h20 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:frrouting:frrouting:8.5.1:*:*:*:*:*:*:*

Informations

Vendor

frrouting

Product

frrouting

Version

8.5.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-44070 2024-08-19 00h00 +00:00 An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
9.8
Critical
CVE-2024-27913 2024-02-28 00h00 +00:00 ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
6.5
Medium
CVE-2023-47234 2023-11-02 23h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
7.5
High
CVE-2023-47235 2023-11-02 23h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
7.5
High
CVE-2023-46752 2023-10-25 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
5.9
Medium
CVE-2023-46753 2023-10-25 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
5.9
Medium
CVE-2023-41909 2023-09-04 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
7.5
High
CVE-2023-38802 2023-08-28 22h00 +00:00 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
7.5
High
CVE-2023-41358 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
7.5
High
CVE-2023-41359 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
9.1
Critical
CVE-2023-41360 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
9.1
Critical
CVE-2023-41361 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
9.8
Critical