First published: Fri Nov 03 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/frr | <9.0.1 | 9.0.1 |
Frrouting Frrouting | <=9.0.1 | |
debian/frr | <=7.5.1-1.1+deb11u2<=8.4.4-1.1~deb12u1 | 7.5.1-1.1+deb11u3 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-47234.
The severity of CVE-2023-47234 is high (7.5).
The affected software version for CVE-2023-47234 is FRRouting FRR up to and including version 9.0.1.
The vulnerability can cause a crash when processing a crafted BGP UPDATE message with a specific attribute and additional data.
To fix CVE-2023-47234, you should update FRRouting to a version that is not affected by this vulnerability.