Bug 1223795

Summary: VUL-0: CVE-2023-46565: metallb: gobgp: buffer overflow via handlingError() function in pkg/server/fsm.go
Product: [openSUSE] openSUSE Distribution Reporter: Camila Camargo de Matos <camila.matos>
Component: SecurityAssignee: Security Team bot <security-team>
Status: NEW --- QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: camila.matos, qa-bugs, screening-team-bugs, smash_bz
Version: Leap 15.6   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/403566/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on:    
Bug Blocks: 1223793    

Description Camila Camargo de Matos 2024-05-02 19:22:46 UTC
+++ This bug was initially created as a clone of Bug #1223793 +++

Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46565
https://www.cve.org/CVERecord?id=CVE-2023-46565
https://github.com/osrg/gobgp/issues/2725
https://bugzilla.redhat.com/show_bug.cgi?id=2278569
Comment 2 Thorsten Kukuk 2024-05-02 20:16:36 UTC
I'm not the maintainer anymore. When we stopped openSUSE Kubic people from the openSUSE Community decided to take over when we wanted to remove the packages. But seems that it is meanwhile unmaintained.