CVE-2023-47234

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Configurations

Configuration 1 (hide)

cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*

History

28 Apr 2024, 07:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html -

14 Nov 2023, 14:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf - (MISC) https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf - Patch
First Time Frrouting frrouting
Frrouting
CPE cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

03 Nov 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-03 21:15

Updated : 2024-04-28 07:15


NVD link : CVE-2023-47234

Mitre link : CVE-2023-47234

CVE.ORG link : CVE-2023-47234


JSON object : View

Products Affected

frrouting

  • frrouting