Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-34088
HistoryApr 30, 2024 - 12:00 a.m.

CVE-2024-34088

2024-04-3000:00:00
ubuntu.com
ubuntu.com
3
frrouting
ospf
daemon
denial of service
vulnerability
get_edge function
quagga project
renamed
crashes

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function
in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where
calling functions do not handle the returned NULL value, the OSPF daemon
crashes, leading to denial of service.

Notes

Author Note
sbeattie the quagga project was renamed to frr
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchfrr< 8.1-1ubuntu1.10UNKNOWN
ubuntu23.10noarchfrr< 8.4.4-1.1ubuntu1.4UNKNOWN
ubuntu24.04noarchfrr< 8.4.4-1.1ubuntu6.1UNKNOWN

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%