CVE-2023-38407: High severity frrouting bgpd vulnerability
Published Nov 6, 2023
·Updated
bgpd/bgplabel.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Affected Software
3 affected componentsFixes available
redhat/ffr<8.5
8.5
Frrouting FRRouting<8.5
debian/frr<=7.5.1-1.1+deb11u2, <=8.4.4-1.1~deb12u1
7.5.1-1.1+deb11u410.2.1-2
Remediation
Patch Available
Patch Available
Event History
Nov 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·06:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38407?
The severity of CVE-2023-38407 is high with a score of 7.5.
2
What is the affected software for CVE-2023-38407?
The affected software for CVE-2023-38407 is FRRouting (FRR) before version 8.5.
3
How does CVE-2023-38407 impact FRRouting?
CVE-2023-38407 in FRRouting can lead to a read beyond the end of the stream during labeled unicast parsing.
4
Are there any fixes available for CVE-2023-38407?
Yes, fixes for CVE-2023-38407 are available in the FRRouting repository on GitHub.
5
Where can I find more information about CVE-2023-38407?
You can find more information about CVE-2023-38407 in the FRRouting repository on GitHub.