Vulnerabilities
Vulnerable Software
Frrouting:  >> Frrouting  >> 9.0.3  Security Vulnerabilities
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-08-19
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-04-30
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-07
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-04-07
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-07
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
CVSS Score
6.5
EPSS Score
0.0
Published
2024-04-07


Contact Us

Shodan ® - All rights reserved