7.5
CVSSv3

CVE-2023-3748

Published: 24/07/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an malicious user to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

frrouting frrouting

Vendor Advisories

Debian Bug report logs - #1042473 frr: CVE-2023-3748 Package: src:frr; Maintainer for src:frr is David Lamparter <equinox-debian@diac24net>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 28 Jul 2023 21:00:02 UTC Severity: important Tags: security, upstream Found in version frr/844-1 Forwarde ...