Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d386daf by Aron Xu at 2023-09-01T12:23:06+08:00
Triage CVEs for frr

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -457,6 +457,8 @@ CVE-2023-39266 (A vulnerability in the ArubaOS-Switch web 
management interface c
 CVE-2023-38802 (FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow 
a remote ...)
        - frr <unfixed>
        NOTE: 
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
+       NOTE: https://github.com/FRRouting/frr/pull/14290
+       NOTE: 
https://github.com/FRRouting/frr/pull/14290/commits/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186
 CVE-2023-38283 (In OpenBGPD before 8.1, incorrect handling of BGP update data 
(length  ...)
        - openbgpd 8.1-1
        NOTE: 
https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig
@@ -598,18 +600,21 @@ CVE-2023-41363 (In Cerebrate 1.14, a vulnerability in 
UserSettingsController all
        NOT-FOR-US: Cerebrate
 CVE-2023-41361 (An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c 
does not ...)
        - frr <unfixed>
+       [bullseye] - frr <not-affected> (The vulnerable code was introduced 
later)
        NOTE: https://github.com/FRRouting/frr/pull/14241
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/b4d09af9194d20a7f9f16995a062f5d8e3d32840
        NOTE: Backport for 9.0 branch: 
https://github.com/FRRouting/frr/pull/14250
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/73ad93a83f18564bb7bff4659872f7ec1a64b05e
 CVE-2023-41360 (An issue was discovered in FRRouting FRR through 9.0. 
bgpd/bgp_packet. ...)
        - frr <unfixed>
+       [bullseye] - frr <not-affected> (The vulnerable code was introduced 
later)
        NOTE: https://github.com/FRRouting/frr/pull/14245
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/9b855a692e68e0d16467e190b466b4ecb6853702
        NOTE: Backport for stable/8.5: 
https://github.com/FRRouting/frr/pull/14249
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/3515178de4a56d66ed948a774efcbe4a854e1ca7
 CVE-2023-41359 (An issue was discovered in FRRouting FRR through 9.0. There is 
an out- ...)
        - frr <unfixed>
+       [bullseye] - frr <not-affected> (The vulnerable code was introduced 
later)
        NOTE: https://github.com/FRRouting/frr/pull/14232
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/f96201e104892e18493f24cf67bb713678e8237b
        NOTE: Backport for stable/8.5: 
https://github.com/FRRouting/frr/pull/14268
@@ -5670,6 +5675,7 @@ CVE-2023-3750 (A flaw was found in libvirt. The 
virStoragePoolObjListSearch func
        NOTE: Fixed by: 
https://gitlab.com/libvirt/libvirt/-/commit/9a47442366fcf8a7b6d7422016d7bbb6764a1098
 (v9.6.0-rc1)
 CVE-2023-3748 (A flaw was found in FRRouting when parsing certain babeld 
unicast hell ...)
        - frr <unfixed> (bug #1042473)
+       [bullseye] - frr <not-affected> (The vulnerable code was introduced 
later)
        [buster] - frr <not-affected> (The vulnerable code was introduced later)
        NOTE: https://github.com/FRRouting/frr/issues/11808
        NOTE: https://github.com/FRRouting/frr/pull/12950
@@ -13855,7 +13861,8 @@ CVE-2023-31490 (An issue found in Frrouting bgpd 
v.8.4.2 allows a remote attacke
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/06431bfa7570f169637ebb5898f0b0cc3b010802
 CVE-2023-31489 (An issue found in Frrouting bgpd v.8.4.2 allows a remote 
attacker to c ...)
        - frr 8.4.4-1 (bug #1036061)
-       [buster] - frr <no-dsa> (Minor issue)
+       [bullseye] - frr <not-affected> (The vulnerable code was introduced 
later)
+       [buster] - frr <not-affected> (The vulnerable code was introduced later)
        NOTE: https://github.com/FRRouting/frr/issues/13098
        NOTE: Fixed by: 
https://github.com/FRRouting/frr/commit/b1d33ec293e8e36fbb8766252f3b016d268e31ce
 CVE-2023-31476 (An issue was discovered on GL.iNet devices running firmware 
before 3.2 ...)
@@ -79538,7 +79545,6 @@ CVE-2022-36441 (An issue was discovered in Zebra 
Enterprise Home Screen 4.1.19.
        NOT-FOR-US: Zebra Enterprise Home Screen
 CVE-2022-36440 (A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in 
the pee ...)
        - frr 8.4.1-1
-       [bullseye] - frr <ignored> (Minor issue, requires untrivial porting)
        [buster] - frr <ignored> (Minor issue)
        NOTE: https://github.com/FRRouting/frr/issues/13202
        NOTE: 
https://github.com/FRRouting/frrcommit/3e46b43e3788f0f87bae56a86b54d412b4710286 
(base_8.4)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to