Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case. NOTE: this behavior occurs in bgp_open_option_parse in the bgp_open.c file, a different location (with a different attack vector) relative to CVE-2022-40302.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FRRouting FRR 缓冲区错误漏洞
Vulnerability Description
FRRouting FRR是一套对各种IPV4和IPV6路由协议进行实现和管理的软件。 FRRouting FRR 存在安全漏洞,该漏洞源于通过制作带有 0xff 类型选项的 BGP OPEN 消息可以导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A