Headline
Ubuntu Security Notice USN-6481-1
Ubuntu Security Notice 6481-1 - It was discovered that FRR incorrectly handled certain malformed NLRI data. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. It was discovered that FRR incorrectly handled certain BGP UPDATE messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service.
==========================================================================Ubuntu Security Notice USN-6481-1November 15, 2023frr vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.10- Ubuntu 23.04- Ubuntu 22.04 LTSSummary:FRR could be made to crash if it received specially crafted networktraffic.Software Description:- frr: FRRouting suite of internet protocolsDetails:It was discovered that FRR incorrectly handled certain malformed NLRI data.A remote attacker could possibly use this issue to cause FRR to crash,resulting in a denial of service. (CVE-2023-46752)It was discovered that FRR incorrectly handled certain BGP UPDATE messages.A remote attacker could possibly use this issue to cause FRR to crash,resulting in a denial of service. (CVE-2023-46753)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.10: frr 8.4.4-1.1ubuntu1.1Ubuntu 23.04: frr 8.4.2-1ubuntu1.5Ubuntu 22.04 LTS: frr 8.1-1ubuntu1.7In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-6481-1 CVE-2023-46752, CVE-2023-46753Package Information: https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu1.1 https://launchpad.net/ubuntu/+source/frr/8.4.2-1ubuntu1.5 https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.7
Related news
Ubuntu Security Notice 6482-1 - It was discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service.
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.