PT-2023-9206 · Frrouting+9 · Frrouting+9

Iggy Frankovic

·

Published

2023-03-05

·

Updated

2024-11-28

·

CVE-2023-38407

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions prior to 8.5
Description The issue is related to the bgpd/bgp label.c file in FRRouting, which attempts to read beyond the end of the stream during labeled unicast parsing. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 8.5, update to version 8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the bgpd/bgp label.c component until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0130
ALSA-2024:0477
BDU:2024-04616
CESA-2024_0130
CVE-2023-38407
DLA-3797-1
DLA-3865-1
OPENSUSE-SU-2024:13487-1
OPENSUSE-SU-2024_2245-1
OPENSUSE-SU-2024_4090-1
RHSA-2024:0130
RHSA-2024:0477
RHSA-2024:0574
RHSA-2024:1093
RHSA-2024:1113
RHSA-2024:1152
RHSA-2024_0130
RHSA-2024_0477
RLSA-2024:0130
SUSE-SU-2023:4663-1
SUSE-SU-2024:2245-1
SUSE-SU-2024:4090-1
USN-6498-1
USN-6807-1

Affected Products

Almalinux
Centos
Debian
Frrouting
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu