Aron Xu pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7d386daf by Aron Xu at 2023-09-01T12:23:06+08:00
Triage CVEs for frr
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -457,6 +457,8 @@ CVE-2023-39266 (A vulnerability in the ArubaOS-Switch web
management interface c
CVE-2023-38802 (FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow
a remote ...)
- frr <unfixed>
NOTE:
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
+ NOTE: https://github.com/FRRouting/frr/pull/14290
+ NOTE:
https://github.com/FRRouting/frr/pull/14290/commits/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186
CVE-2023-38283 (In OpenBGPD before 8.1, incorrect handling of BGP update data
(length ...)
- openbgpd 8.1-1
NOTE:
https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig
@@ -598,18 +600,21 @@ CVE-2023-41363 (In Cerebrate 1.14, a vulnerability in
UserSettingsController all
NOT-FOR-US: Cerebrate
CVE-2023-41361 (An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c
does not ...)
- frr <unfixed>
+ [bullseye] - frr <not-affected> (The vulnerable code was introduced
later)
NOTE: https://github.com/FRRouting/frr/pull/14241
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/b4d09af9194d20a7f9f16995a062f5d8e3d32840
NOTE: Backport for 9.0 branch:
https://github.com/FRRouting/frr/pull/14250
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/73ad93a83f18564bb7bff4659872f7ec1a64b05e
CVE-2023-41360 (An issue was discovered in FRRouting FRR through 9.0.
bgpd/bgp_packet. ...)
- frr <unfixed>
+ [bullseye] - frr <not-affected> (The vulnerable code was introduced
later)
NOTE: https://github.com/FRRouting/frr/pull/14245
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/9b855a692e68e0d16467e190b466b4ecb6853702
NOTE: Backport for stable/8.5:
https://github.com/FRRouting/frr/pull/14249
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/3515178de4a56d66ed948a774efcbe4a854e1ca7
CVE-2023-41359 (An issue was discovered in FRRouting FRR through 9.0. There is
an out- ...)
- frr <unfixed>
+ [bullseye] - frr <not-affected> (The vulnerable code was introduced
later)
NOTE: https://github.com/FRRouting/frr/pull/14232
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/f96201e104892e18493f24cf67bb713678e8237b
NOTE: Backport for stable/8.5:
https://github.com/FRRouting/frr/pull/14268
@@ -5670,6 +5675,7 @@ CVE-2023-3750 (A flaw was found in libvirt. The
virStoragePoolObjListSearch func
NOTE: Fixed by:
https://gitlab.com/libvirt/libvirt/-/commit/9a47442366fcf8a7b6d7422016d7bbb6764a1098
(v9.6.0-rc1)
CVE-2023-3748 (A flaw was found in FRRouting when parsing certain babeld
unicast hell ...)
- frr <unfixed> (bug #1042473)
+ [bullseye] - frr <not-affected> (The vulnerable code was introduced
later)
[buster] - frr <not-affected> (The vulnerable code was introduced later)
NOTE: https://github.com/FRRouting/frr/issues/11808
NOTE: https://github.com/FRRouting/frr/pull/12950
@@ -13855,7 +13861,8 @@ CVE-2023-31490 (An issue found in Frrouting bgpd
v.8.4.2 allows a remote attacke
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/06431bfa7570f169637ebb5898f0b0cc3b010802
CVE-2023-31489 (An issue found in Frrouting bgpd v.8.4.2 allows a remote
attacker to c ...)
- frr 8.4.4-1 (bug #1036061)
- [buster] - frr <no-dsa> (Minor issue)
+ [bullseye] - frr <not-affected> (The vulnerable code was introduced
later)
+ [buster] - frr <not-affected> (The vulnerable code was introduced later)
NOTE: https://github.com/FRRouting/frr/issues/13098
NOTE: Fixed by:
https://github.com/FRRouting/frr/commit/b1d33ec293e8e36fbb8766252f3b016d268e31ce
CVE-2023-31476 (An issue was discovered on GL.iNet devices running firmware
before 3.2 ...)
@@ -79538,7 +79545,6 @@ CVE-2022-36441 (An issue was discovered in Zebra
Enterprise Home Screen 4.1.19.
NOT-FOR-US: Zebra Enterprise Home Screen
CVE-2022-36440 (A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in
the pee ...)
- frr 8.4.1-1
- [bullseye] - frr <ignored> (Minor issue, requires untrivial porting)
[buster] - frr <ignored> (Minor issue)
NOTE: https://github.com/FRRouting/frr/issues/13202
NOTE:
https://github.com/FRRouting/frrcommit/3e46b43e3788f0f87bae56a86b54d412b4710286
(base_8.4)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits