PT-2023-2523 · Frrouting+4 · Frrouting+4

CVE-2022-40302

·

Publicado

2023-01-22

·

Atualizado

2024-04-03

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions through 8.4
Description An issue in bgpd allows attackers to cause a denial of service by crafting a BGP OPEN message with an option of type 0xff, leading to inconsistent boundary checks and potential out-of-bounds read or assertion failure and daemon restart.
Recommendations For versions through 8.4, consider disabling the BGP OPEN message handler until a patch is available to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:6434
ALT-PU-2023-1111
BDU:2023-02322
CVE-2022-40302
DLA-3573-1
DSA-5495-1
RHSA-2023:6434
RHSA-2023_6434

Produtos afetados

Alt Linux
Almalinux
Frrouting
Red Hat
Red Os