FRRouting (FRR) 9.0.2

CPE Details

FRRouting (FRR) 9.0.2
9.0.2
2024-08-20
10h10 +00:00
2024-08-20
10h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:frrouting:frrouting:9.0.2:*:*:*:*:*:*:*

Informations

Vendor

frrouting

Product

frrouting

Version

9.0.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-44070 2024-08-19 00h00 +00:00 An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
9.8
Critical
CVE-2024-34088 2024-04-29 22h00 +00:00 In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
7.5
High
CVE-2024-31949 2024-04-07 00h00 +00:00 In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
6.5
Medium
CVE-2024-31948 2024-04-06 22h00 +00:00 In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
6.5
Medium
CVE-2024-31950 2024-04-06 22h00 +00:00 In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
6.5
Medium
CVE-2024-31951 2024-04-06 22h00 +00:00 In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
6.5
Medium