[Git][security-tracker-team/security-tracker][master] Track fixed version for three CVEs for frr fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 1 18:34:32 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
24188544 by Salvatore Bonaccorso at 2023-09-01T19:34:02+02:00
Track fixed version for three CVEs for frr fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -525,7 +525,7 @@ CVE-2023-39267 (An authenticated remote code execution vulnerability exists in t
 CVE-2023-39266 (A vulnerability in the ArubaOS-Switch web management interface could a ...)
 	NOT-FOR-US: Aruba
 CVE-2023-38802 (FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote ...)
-	- frr <unfixed>
+	- frr 8.4.4-1.1
 	NOTE: https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
 	NOTE: https://github.com/FRRouting/frr/pull/14290
 	NOTE: https://github.com/FRRouting/frr/commit/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186
@@ -678,7 +678,7 @@ CVE-2023-41361 (An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c do
 	NOTE: Backport for 9.0 branch: https://github.com/FRRouting/frr/pull/14250
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/73ad93a83f18564bb7bff4659872f7ec1a64b05e
 CVE-2023-41360 (An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet. ...)
-	- frr <unfixed>
+	- frr 8.4.4-1.1
 	[bullseye] - frr <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://github.com/FRRouting/frr/pull/14245
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/9b855a692e68e0d16467e190b466b4ecb6853702
@@ -692,7 +692,7 @@ CVE-2023-41359 (An issue was discovered in FRRouting FRR through 9.0. There is a
 	NOTE: Backport for stable/8.5: https://github.com/FRRouting/frr/pull/14268
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/460ee930d6dbce6e96ecbfcd568a291f31bae24e
 CVE-2023-41358 (An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet. ...)
-	- frr <unfixed>
+	- frr 8.4.4-1.1
 	NOTE: https://github.com/FRRouting/frr/pull/14260
 	NOTE: Fixed by: https://github.com/FRRouting/frr/commit/28ccc24d38df1d51ed8a563507e5d6f6171fdd38
 	NOTE: Backport for stable/8.5: https://github.com/FRRouting/frr/pull/14270



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24188544b0edccf589f9f5a3decbad8b03cdf1b2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24188544b0edccf589f9f5a3decbad8b03cdf1b2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230901/c4471f0b/attachment.htm>


More information about the debian-security-tracker-commits mailing list