← Back to CVE Index

CVE-2023-41360

Disclosed 2023-08-29

Description

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

Severity & CVSS Score

9.1 CRITICAL CVSS 3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Weakness Enumeration

CWE-IDName
CWE-125 Out-of-bounds Read

Affected FRR Versions

  • 8.4.x
  • 8.5.0 ~ 8.5.2
  • 9.0.0

Versions prior to 8.4 are end-of-life and no longer receive security updates.

References

URLSource
https://github.com/FRRouting/frr/pull/14245/commits/9b855a692e68e0d16467e190b466b4ecb6853702 GitHub

Git Fixes

Raw Data