Vulnerabilities
Vulnerable Software
Frrouting:  >> Frrouting  >> 9.0.1  Security Vulnerabilities
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-08-19
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-04-30
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-07
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-04-07
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-07
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
CVSS Score
6.5
EPSS Score
0.0
Published
2024-04-07
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
CVSS Score
7.5
EPSS Score
0.001
Published
2023-11-03
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-11-03
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-10-26
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-10-26


Contact Us

Shodan ® - All rights reserved