CVE-2023-47234
03.11.2023, 21:15
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frrouting | frrouting | 𝑥 ≤ 9.0.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| frrouting | frrouting | 𝑥 ≤ 9.0.1 | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| frr |
| ||||||||||||||||||
| quagga |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| frr |
| ||||||||||||||||||||
| frr-devel |
| ||||||||||||||||||||
| libfrr0 |
| ||||||||||||||||||||
| libfrr_pb0 |
| ||||||||||||||||||||
| libfrrcares0 |
| ||||||||||||||||||||
| libfrrfpm_pb0 |
| ||||||||||||||||||||
| libfrrgrpc_pb0 |
| ||||||||||||||||||||
| libfrrospfapiclient0 |
| ||||||||||||||||||||
| libfrrsnmp0 |
| ||||||||||||||||||||
| libfrrzmq0 |
| ||||||||||||||||||||
| libmgmt_be_nb0 |
| ||||||||||||||||||||
| libmlag_pb0 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| frr |
| ||||||||||||
| frr-selinux |
|
References