Bug 1223795 - VUL-0: CVE-2023-46565: metallb: gobgp: buffer overflow via handlingError() function in pkg/server/fsm.go
Summary: VUL-0: CVE-2023-46565: metallb: gobgp: buffer overflow via handlingError() fu...
Status: NEW
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/403566/
Whiteboard:
Keywords:
Depends on:
Blocks: CVE-2023-46565
  Show dependency treegraph
 
Reported: 2024-05-02 19:22 UTC by Camila Camargo de Matos
Modified: 2024-05-21 04:08 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Camila Camargo de Matos 2024-05-02 19:22:46 UTC
+++ This bug was initially created as a clone of Bug #1223793 +++

Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46565
https://www.cve.org/CVERecord?id=CVE-2023-46565
https://github.com/osrg/gobgp/issues/2725
https://bugzilla.redhat.com/show_bug.cgi?id=2278569
Comment 2 Thorsten Kukuk 2024-05-02 20:16:36 UTC
I'm not the maintainer anymore. When we stopped openSUSE Kubic people from the openSUSE Community decided to take over when we wanted to remove the packages. But seems that it is meanwhile unmaintained.