FRRouting 8.4.3

CPE Details

FRRouting 8.4.3
8.4.3
2023-05-16
15h33 +00:00
2023-05-22
11h20 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:frrouting:frrouting:8.4.3:*:*:*:*:*:*:*

Informations

Vendor

frrouting

Product

frrouting

Version

8.4.3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-44070 2024-08-19 00h00 +00:00 An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
9.8
Critique
CVE-2024-27913 2024-02-28 00h00 +00:00 ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
6.5
Moyen
CVE-2023-38407 2023-11-05 23h00 +00:00 bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
7.5
Haute
CVE-2023-47234 2023-11-02 23h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
7.5
Haute
CVE-2023-47235 2023-11-02 23h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
7.5
Haute
CVE-2023-46752 2023-10-25 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
5.9
Moyen
CVE-2023-46753 2023-10-25 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
5.9
Moyen
CVE-2023-41909 2023-09-04 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
7.5
Haute
CVE-2023-38802 2023-08-28 22h00 +00:00 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
7.5
Haute
CVE-2023-41358 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
7.5
Haute
CVE-2023-41359 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
9.1
Critique
CVE-2023-41360 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
9.1
Critique
CVE-2023-41361 2023-08-28 22h00 +00:00 An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
9.8
Critique
CVE-2023-3748 2023-07-24 15h19 +00:00 A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
7.5
Haute