CVE-2017-15865

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:*:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc0:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:frrouting:frrouting:3.0.1:*:*:*:*:*:*:*
cpe:2.3:o:cumulusnetworks:cumulus_linux:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/101794 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101794 - Third Party Advisory, VDB Entry
References () https://frrouting.org/community/security.html - Issue Tracking, Vendor Advisory () https://frrouting.org/community/security.html - Issue Tracking, Vendor Advisory
References () https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-November/000009.html - Issue Tracking, Third Party Advisory () https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-November/000009.html - Issue Tracking, Third Party Advisory
References () https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690 - Issue Tracking, Third Party Advisory () https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690 - Issue Tracking, Third Party Advisory
References () https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-15865-Malformed-BGP-UPDATE-Triggers-Information-Disclosure - Issue Tracking, Third Party Advisory () https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-15865-Malformed-BGP-UPDATE-Triggers-Information-Disclosure - Issue Tracking, Third Party Advisory

Information

Published : 2017-11-08 20:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-15865

Mitre link : CVE-2017-15865

CVE.ORG link : CVE-2017-15865


JSON object : View

Products Affected

cumulusnetworks

  • cumulus_linux

frrouting

  • frrouting
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor