An issue was discovered in FRRouting (FRR) through 10.1. bgpattrencap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-bgpd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-bgpd-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-core" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-core-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-doc" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-isisd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-isisd-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ospf6d" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ospf6d-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ospfd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ospfd-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-pimd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-pimd-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ripd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ripd-dbgsym" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ripngd" }, { "binary_version": "1.2.4-4ubuntu0.5", "binary_name": "quagga-ripngd-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-dbgsym" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-doc" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-pythontools" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-rpki-rtrlib" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-rpki-rtrlib-dbgsym" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-snmp" }, { "binary_version": "8.1-1ubuntu1.11", "binary_name": "frr-snmp-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-dbgsym" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-doc" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-pythontools" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-rpki-rtrlib" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-rpki-rtrlib-dbgsym" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-snmp" }, { "binary_version": "10.0.1-0.1ubuntu2", "binary_name": "frr-snmp-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-dbgsym" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-doc" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-pythontools" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-rpki-rtrlib" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-rpki-rtrlib-dbgsym" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-snmp" }, { "binary_version": "8.4.4-1.1ubuntu6.2", "binary_name": "frr-snmp-dbgsym" } ] }