[Git][security-tracker-team/security-tracker][master] Triage CVEs for frr

Aron Xu (@aron) aron at debian.org
Fri Sep 1 05:23:23 BST 2023



Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d386daf by Aron Xu at 2023-09-01T12:23:06+08:00
Triage CVEs for frr

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -457,6 +457,8 @@ CVE-2023-39266 (A vulnerability in the ArubaOS-Switch web management interface c
 CVE-2023-38802 (FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote ...)
 	- frr <unfixed>
 	NOTE: https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
+	NOTE: https://github.com/FRRouting/frr/pull/14290
+	NOTE: https://github.com/FRRouting/frr/pull/14290/commits/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186
 CVE-2023-38283 (In OpenBGPD before 8.1, incorrect handling of BGP update data (length  ...)
 	- openbgpd 8.1-1
 	NOTE: https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig
@@ -598,18 +600,21 @@ CVE-2023-41363 (In Cerebrate 1.14, a vulnerability in UserSettingsController all
 	NOT-FOR-US: Cerebrate
 CVE-2023-41361 (An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not ...)
 	- frr <unfixed>
+	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/pull/14241
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/b4d09af9194d20a7f9f16995a062f5d8e3d32840
 	NOTE: Backport for 9.0 branch: https://github.com/FRRouting/frr/pull/14250
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/73ad93a83f18564bb7bff4659872f7ec1a64b05e
 CVE-2023-41360 (An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet. ...)
 	- frr <unfixed>
+	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/pull/14245
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/9b855a692e68e0d16467e190b466b4ecb6853702
 	NOTE: Backport for stable/8.5: https://github.com/FRRouting/frr/pull/14249
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/3515178de4a56d66ed948a774efcbe4a854e1ca7
 CVE-2023-41359 (An issue was discovered in FRRouting FRR through 9.0. There is an out- ...)
 	- frr <unfixed>
+	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/pull/14232
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/f96201e104892e18493f24cf67bb713678e8237b
 	NOTE: Backport for stable/8.5: https://github.com/FRRouting/frr/pull/14268
@@ -5670,6 +5675,7 @@ CVE-2023-3750 (A flaw was found in libvirt. The virStoragePoolObjListSearch func
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/9a47442366fcf8a7b6d7422016d7bbb6764a1098 (v9.6.0-rc1)
 CVE-2023-3748 (A flaw was found in FRRouting when parsing certain babeld unicast hell ...)
 	- frr <unfixed> (bug #1042473)
+	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
 	[buster] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/issues/11808
 	NOTE: https://github.com/FRRouting/frr/pull/12950
@@ -13855,7 +13861,8 @@ CVE-2023-31490 (An issue found in Frrouting bgpd v.8.4.2 allows a remote attacke
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/06431bfa7570f169637ebb5898f0b0cc3b010802
 CVE-2023-31489 (An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to c ...)
 	- frr 8.4.4-1 (bug #1036061)
-	[buster] - frr <no-dsa> (Minor issue)
+	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
+	[buster] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/issues/13098
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/b1d33ec293e8e36fbb8766252f3b016d268e31ce
 CVE-2023-31476 (An issue was discovered on GL.iNet devices running firmware before 3.2 ...)
@@ -79538,7 +79545,6 @@ CVE-2022-36441 (An issue was discovered in Zebra Enterprise Home Screen 4.1.19.
 	NOT-FOR-US: Zebra Enterprise Home Screen
 CVE-2022-36440 (A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the pee ...)
 	- frr 8.4.1-1
-	[bullseye] - frr <ignored> (Minor issue, requires untrivial porting)
 	[buster] - frr <ignored> (Minor issue)
 	NOTE: https://github.com/FRRouting/frr/issues/13202
 	NOTE: https://github.com/FRRouting/frrcommit/3e46b43e3788f0f87bae56a86b54d412b4710286 (base_8.4)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d386daf1458ae2dc0d6df1ac8f044876dc23d98
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230901/6c9fdf1c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list