VYPR

rpm package

opensuse/frr&distro=openSUSE Leap 15.6

pkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.6

Vulnerabilities (29)

  • CVE-2023-46753Oct 26, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

  • CVE-2023-46752Oct 26, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.

  • CVE-2023-41909Sep 5, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.

  • CVE-2023-41360Aug 29, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

  • CVE-2023-41358Aug 29, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

  • CVE-2023-38802Aug 29, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

  • CVE-2023-3748Jul 24, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV w

  • CVE-2023-31490May 9, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

  • CVE-2023-31489May 9, 2023
    affected < 8.5.6-150500.4.30.1fixed 8.5.6-150500.4.30.1

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.

Page 2 of 2