← Back to CVE Index
CVE-2023-38407
Disclosed 2023-11-06
Description
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Git Fixes
- 7404a914b0cafe046703c8381903a80d3def8f8b
- ab362eae68edec12c175d9bc488bcc3f8b73d36f
- 0b509176be67495c48a3e0c99db901d4da993142
Raw Data
- CVE-2023-38407.cve.json — CVE record (JSON)
- CVE-2023-38407.frr.json — FRR-specific data (JSON)