First published: Mon Nov 06 2023(Updated: )
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ffr | <8.5 | 8.5 |
Frrouting Frrouting | <8.5 | |
debian/frr | <=7.5.1-1.1+deb11u2<=8.4.4-1.1~deb12u1 | 7.5.1-1.1+deb11u3 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38407 is high with a score of 7.5.
The affected software for CVE-2023-38407 is FRRouting (FRR) before version 8.5.
CVE-2023-38407 in FRRouting can lead to a read beyond the end of the stream during labeled unicast parsing.
Yes, fixes for CVE-2023-38407 are available in the FRRouting repository on GitHub.
You can find more information about CVE-2023-38407 in the FRRouting repository on GitHub.