PT-2024-6035 · Frrouting+6 · Frrouting+6
Published
2024-04-07
·
Updated
2024-12-09
·
CVE-2024-34088
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FRRouting versions through 9.1
Description
The issue is related to the
get edge() function in the ospf te.c file of the OSPF daemon component in FRRouting, which can return a NULL pointer. If calling functions do not handle this NULL value, the OSPF daemon may crash, leading to a denial of service. This can be exploited by a remote attacker to cause service disruption.Recommendations
For FRRouting versions through 9.1, consider disabling the
get edge() function as a temporary workaround until a patch is available. Restrict access to the OSPF daemon to minimize the risk of exploitation. Update to a version later than 9.1 when available.Fix
DoS
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Frrouting
Linuxmint
Red Os
Suse
Ubuntu