Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2022-37032: frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Carlos López <carlos.lopez> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | carlos.lopez, jsegitz, mardnh, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/338551/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2022-37032:7.1:(AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Bug Depends on: | 1196957 | ||
Bug Blocks: |
Description
Carlos López
2022-08-01 10:25:45 UTC
Affected: - SUSE:SLE-15-SP3:Update - openSUSE:Factory Submission request to SLE in https://build.suse.de/request/show/279073 Submission request to network is in https://build.opensuse.org/request/show/1001418 (In reply to Marius Tomaschewski from comment #5) > Submission request to network is in > https://build.opensuse.org/request/show/1001418 On the way to factory in https://build.opensuse.org/request/show/1001456 Assigning back to security-team. SUSE-SU-2022:3246-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1202022,1202023 CVE References: CVE-2019-25074,CVE-2022-37032 JIRA References: Sources used: openSUSE Leap 15.4 (src): frr-7.4-150300.4.7.1 openSUSE Leap 15.3 (src): frr-7.4-150300.4.7.1 SUSE Linux Enterprise Module for Server Applications 15-SP4 (src): frr-7.4-150300.4.7.1 SUSE Linux Enterprise Module for Server Applications 15-SP3 (src): frr-7.4-150300.4.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. Done, closing. |