← Back to CVE Index

CVE-2023-38407

Disclosed 2023-11-06

Description

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

Severity & CVSS Score

7.5 HIGH CVSS 3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

URLSource
https://github.com/FRRouting/frr/pull/12951 GitHub
https://github.com/FRRouting/frr/pull/12956 GitHub
https://github.com/FRRouting/frr/compare/frr-8.5-rc...frr-8.5 GitHub
https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html Debian

Git Fixes

Raw Data