Bug 1214741 (CVE-2023-41361) - VUL-0: CVE-2023-41361: frr,quagga: bgpd/bgp_open.c does not check for an overly large length of the rcv software version
Summary: VUL-0: CVE-2023-41361: frr,quagga: bgpd/bgp_open.c does not check for an over...
Status: RESOLVED INVALID
Alias: CVE-2023-41361
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/376587/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-29 09:16 UTC by Cathy Hu
Modified: 2023-08-29 13:03 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-08-29 09:16:32 UTC
CVE-2023-41361

An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for
an overly large length of the rcv software version.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-41361
https://www.cve.org/CVERecord?id=CVE-2023-41361
https://github.com/FRRouting/frr/pull/14241
Comment 1 Cathy Hu 2023-08-29 09:17:42 UTC
The introducing commit was only added in 9.0: https://github.com/opensourcerouting/frr/commit/234f6fd4f4804bb17bd8cbb1dd91994a914f38d2

We only ship versions lower than that, so tracking as not affected:
- SUSE:SLE-11-SP1:Update/quagga  0.99.15
- SUSE:SLE-12-SP2:Update/quagga  1.1.1  
- SUSE:SLE-15-SP4:Update/quagga  1.1.1  
- SUSE:SLE-15:Update/quagga      1.1.1
- SUSE:SLE-15-SP3:Update/frr     7.4   
- SUSE:SLE-15-SP5:Update/frr     8.4
Comment 4 Cathy Hu 2023-08-29 13:03:44 UTC
closing