Lucene search

K
redosRedosROS-20240607-01
HistoryJun 07, 2024 - 12:00 a.m.

ROS-20240607-01

2024-06-0700:00:00
redos.red-soft.ru
1
vulnerability
bgp_capability_msg_parse
bgp_notify_send_with_data
network routing
unix
frrouting
memory boundaries
exploitation
arbitrary code
bgp packet

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.6 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%

Vulnerability of bgp_capability_msg_parse() functions of a software tool for implementing network routing on Unix-like FRRouting systems is related to reading outside memory boundaries of the BGP FRRouting daemon.
Unix-like systems FRRouting is related to read outside memory boundaries in the BGP FRRouting daemon
FRR. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of
denial of service

Vulnerability in bgp_notify_send_with_data() and bgp_process_packet() (bgp_packet.c) functions of the software implementation tool for network routing on Unix.
means of implementing network routing on Unix-like systems FRRouting is related to memory usage after its release.
memory after it has been freed. Exploitation of the vulnerability could allow an attacker acting remotely,
execute arbitrary code using a specially crafted BGP packet

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64frr<= 9.1-1UNKNOWN

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.6 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%