CVE-2023-41909
published 2023-09-05CVE-2023-41909: An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.93%
57.0th percentile
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | frr | < frr 8.4.4-1 (bookworm) | frr 8.4.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| frrouting | frrouting | <= 9.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa5.9MEDIUM
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache MINA SSHD: integrity check bypass
ghsa·2024-08-12·CVSS 5.9
CVE-2024-41909 [MEDIUM] CWE-354 Apache MINA SSHD: integrity check bypass
Apache MINA SSHD: integrity check bypass
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
OSV
frr vulnerabilities
osv·2023-10-18·CVSS 7.5
CVE-2023-41358 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that the FRR did not properly check the attribute length
in NRLI. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2023-41358)
It was discovered that the FRR did not properly manage memory when reading
initial bytes of ORF header. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-41360)
It was discovered that FRR did not properly validate the attributes in the
BGP FlowSpec functionality. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-41909)
OSV
CVE-2023-41909: An issue was discovered in FRRouting FRR through 9
osv·2023-09-05·CVSS 7.5
CVE-2023-41909 [HIGH] CVE-2023-41909: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
GHSA
GHSA-qvhj-42gp-xfmw: An issue was discovered in FRRouting FRR through 9
ghsa_unreviewed·2023-09-05
CVE-2023-41909 [HIGH] CWE-476 GHSA-qvhj-42gp-xfmw: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Red Hat
mina-sshd: integrity check bypass vulnerability
vendor_redhat·2024-08-12·CVSS 5.9
CVE-2024-41909 [MEDIUM] CWE-354 mina-sshd: integrity check bypass vulnerability
mina-sshd: integrity check bypass vulnerability
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
A flaw was found
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2023-10-18·CVSS 7.5
CVE-2023-41360 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that the FRR did not properly check the attribute length
in NRLI. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2023-41358)
It was discovered that the FRR did not properly manage memory when reading
initial bytes of ORF header. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-41360)
It was discovered that FRR did not properly validate the attributes in the
BGP FlowSpec functionality. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-41909)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c
vendor_redhat·2023-09-05·CVSS 7.5
CVE-2023-41909 [HIGH] CWE-476 frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c
frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
A flaw was found in frr. Processing a malformed request with no attributes may cause a NULL pointer dereference, resulting in a denial of service.
Debian
CVE-2023-41909: frr - An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in...
vendor_debian·2023·CVSS 7.5
CVE-2023-41909 [HIGH] CVE-2023-41909: frr - An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in...
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 8.4.4-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved (fixed in 8.4.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8https://lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8https://lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/
2023-09-05
Published