First published: Fri Nov 03 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/frr | <9.0.1 | 9.0.1 |
Frrouting Frrouting | <=9.0.1 | |
debian/frr | <=7.5.1-1.1+deb11u2<=8.4.4-1.1~deb12u1 | 7.5.1-1.1+deb11u3 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-47235 is high with a severity value of 7.5.
The affected software version of CVE-2023-47235 is Frrouting Frrouting up to version 9.0.1.
CVE-2023-47235 manifests as a crash when a malformed BGP UPDATE message with an EOR is processed.
The crash in CVE-2023-47235 is caused by the presence of EOR in a malformed BGP UPDATE message.
A fix for CVE-2023-47235 is available. Please refer to the reference link for more information.