Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade frr | Aug 22, 2024 | Mar 3, 2022 |
| Debian | — | Upgrade frr | Apr 29, 2024 | Mar 3, 2022 |
| Suse | — | Upgrade libfrrcares0Upgrade libfrrgrpc_pb0Upgrade libfrrfpm_pb0Upgrade libfrrospfapiclient0Upgrade libfrrsnmp0Upgrade frrUpgrade frr-develUpgrade libmlag_pb0Upgrade libfrr0Upgrade libfrr_pb0Upgrade libfrrzmq0 | Mar 19, 2022 | Mar 3, 2022 |
| Ubuntu | — | Upgrade frr (Ubuntu Pro) | Jun 7, 2024 | Mar 3, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub