We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-38802



Assignermitre
Reserved2023-07-25
Published2023-08-29
Updated2024-10-02

Description

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

References

https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling

https://news.ycombinator.com/item?id=37305800

https://www.debian.org/security/2023/dsa-5495 (DSA-5495) vendor-advisory

https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html ([debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update) mailing-list

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/ (FEDORA-2023-514db5339e) vendor-advisory

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/ (FEDORA-2023-ce436d56f8) vendor-advisory

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/ (FEDORA-2023-61abba57d8) vendor-advisory

cve.org CVE-2023-38802

nvd.nist.gov CVE-2023-38802

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.