跳转到帖子

SUSE: CVE-2023-3748: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2023-3748: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
07/24/2023
Created
09/21/2023
Added
09/21/2023
Modified
01/28/2025

Description

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

Solution(s)

  • suse-upgrade-frr
  • suse-upgrade-frr-devel
  • suse-upgrade-libfrr0
  • suse-upgrade-libfrr_pb0
  • suse-upgrade-libfrrcares0
  • suse-upgrade-libfrrfpm_pb0
  • suse-upgrade-libfrrospfapiclient0
  • suse-upgrade-libfrrsnmp0
  • suse-upgrade-libfrrzmq0
  • suse-upgrade-libmlag_pb0

References

  • https://attackerkb.com/topics/cve-2023-3748
  • CVE - 2023-3748
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…