CVE-2023-47235: High severity frrouting bgpd vulnerability
Published Nov 3, 2023
·Updated
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
Affected Software
3 affected componentsFixes available
redhat/frr<9.0.1
9.0.1
Frrouting FRRouting<=9.0.1
debian/frr<=7.5.1-1.1+deb11u2, <=8.4.4-1.1~deb12u1
7.5.1-1.1+deb11u410.2.1-2
Remediation
Event History
Nov 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·06:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47235?
The severity of CVE-2023-47235 is high with a severity value of 7.5.
2
What software versions are affected by CVE-2023-47235?
The affected software version of CVE-2023-47235 is Frrouting Frrouting up to version 9.0.1.
3
How does CVE-2023-47235 manifest?
CVE-2023-47235 manifests as a crash when a malformed BGP UPDATE message with an EOR is processed.
4
What is the cause of the crash in CVE-2023-47235?
The crash in CVE-2023-47235 is caused by the presence of EOR in a malformed BGP UPDATE message.
5
Is there a fix available for CVE-2023-47235?
A fix for CVE-2023-47235 is available. Please refer to the reference link for more information.