CVE-2023-38283

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2023
Last modified:
07/09/2023

Description

In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbgpd:openbgpd:*:*:*:*:*:*:*:* 8.1 (excluding)
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* 7.3 (excluding)
cpe:2.3:o:openbsd:openbsd:7.3:-:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_001:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_002:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_003:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_004:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_005:*:*:*:*:*:*