Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2024-44070
Disclosure Date: August 19, 2024 (last updated August 31, 2024)
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
0
Attacker Value
Unknown
CVE-2024-27913
Disclosure Date: February 28, 2024 (last updated January 22, 2025)
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
0
Attacker Value
Unknown
CVE-2023-38407
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
0
Attacker Value
Unknown
CVE-2023-38406
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
0
Attacker Value
Unknown
CVE-2023-47235
Disclosure Date: November 03, 2023 (last updated November 15, 2023)
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
0
Attacker Value
Unknown
CVE-2023-47234
Disclosure Date: November 03, 2023 (last updated November 15, 2023)
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
0
Attacker Value
Unknown
CVE-2023-46753
Disclosure Date: October 26, 2023 (last updated November 10, 2023)
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
0
Attacker Value
Unknown
CVE-2023-46752
Disclosure Date: October 26, 2023 (last updated November 14, 2023)
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
0
Attacker Value
Unknown
CVE-2023-41909
Disclosure Date: September 05, 2023 (last updated December 23, 2023)
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2023-38802
Disclosure Date: August 29, 2023 (last updated December 23, 2023)
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
0