CVE-2023-47234: High severity frrouting bgpd vulnerability
Published Nov 3, 2023
·Updated
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MPUNREACHNLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Affected Software
3 affected componentsFixes available
redhat/frr<9.0.1
9.0.1
Frrouting FRRouting<=9.0.1
debian/frr<=7.5.1-1.1+deb11u2, <=8.4.4-1.1~deb12u1
7.5.1-1.1+deb11u410.2.1-2
Remediation
Event History
Nov 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·06:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-47234.
2
What is the severity of CVE-2023-47234?
The severity of CVE-2023-47234 is high (7.5).
3
What is the affected software version for CVE-2023-47234?
The affected software version for CVE-2023-47234 is FRRouting FRR up to and including version 9.0.1.
4
What is the impact of this vulnerability?
The vulnerability can cause a crash when processing a crafted BGP UPDATE message with a specific attribute and additional data.
5
How can I fix the vulnerability CVE-2023-47234?
To fix CVE-2023-47234, you should update FRRouting to a version that is not affected by this vulnerability.