PT-2023-7215 · Frrouting+10 · Frrouting+10

Iggy Frankovic

·

Published

2023-10-25

·

Updated

2024-11-28

·

CVE-2023-46752

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FRRouting versions through 9.0.1
Description The issue is related to insufficient input validation in FRRouting, which can be exploited by a remote attacker to cause a denial of service. Specifically, it mishandles malformed MP REACH NLRI data, leading to a crash.
Recommendations For versions through 9.0.1, consider disabling the handling of MP REACH NLRI data as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ALSA-2024:2156
ALSA-2024:2981
ALT-PU-2024-1188
ALT-PU-2024-2047
AZL-31700
AZL-34692
BDU:2023-08243
CESA-2024_2981
CVE-2023-46752
DLA-3797-1
DLA-3865-1
INFSA-2024_2156
INFSA-2024_2981
OPENSUSE-SU-2023_4473-1
OPENSUSE-SU-2023_4483-1
OPENSUSE-SU-2024:13387-1
OPENSUSE-SU-2024_4090-1
RHSA-2024:2156
RHSA-2024:2981
RHSA-2024_2156
RHSA-2024_2981
SUSE-SU-2023:4473-1
SUSE-SU-2023:4483-1
SUSE-SU-2023_4473-1
SUSE-SU-2023_4483-1
SUSE-SU-2024:4090-1
USN-6481-1
USN-6807-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Frrouting
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu