FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 08:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling - Exploit, Technical Description, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/ - Mailing List | |
References | () https://news.ycombinator.com/item?id=37305800 - Third Party Advisory | |
References | () https://www.debian.org/security/2023/dsa-5495 - Third Party Advisory |
22 Dec 2023, 21:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-29 16:15
Updated : 2024-11-21 08:14
NVD link : CVE-2023-38802
Mitre link : CVE-2023-38802
CVE.ORG link : CVE-2023-38802
JSON object : View
Products Affected
pica8
- picos
fedoraproject
- fedora
frrouting
- frrouting
debian
- debian_linux
CWE
CWE-354
Improper Validation of Integrity Check Value