Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x before 6.0.2 (not affecting Cumulus Linux or VyOS), when ENABLE_BGP_VNC is used for Virtual Network Control, allows remote attackers to cause a denial of service (peering session flap) via attribute 255 in a BGP UPDATE packet. This occurred during Disco in January 2019 because FRR does not implement RFC 7606, and therefore the packets with 255 were considered invalid VNC data and the BGP session was closed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FRRouting FRR 输入验证错误漏洞
Vulnerability Description
FRRouting FRR是一套对各种IPV4和IPV6路由协议进行实现和管理的软件。 FRRouting FRR中的bgpd存在安全漏洞。远程攻击者可利用该漏洞造成拒绝服务。以下版本受到影响:FRRouting FRR 2.x版本,3.0.4之前的3.x版本,4.0.1之前的4.x版本,5.0.2之前的5.x版本,6.0.2之前的6.x版本(不影响Cumulus Linux或VyOS)。
CVSS Information
N/A
Vulnerability Type
N/A