Vulnerability Description
bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frrouting | Frrouting | < 2.0.2 |
| Cumulusnetworks | Cumulus Linux | < 3.4.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101794Third Party AdvisoryVDB Entry
- https://frrouting.org/community/security.htmlIssue TrackingVendor Advisory
- https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-NovemIssue TrackingThird Party Advisory
- https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690Issue TrackingThird Party Advisory
- https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-1586Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/101794Third Party AdvisoryVDB Entry
- https://frrouting.org/community/security.htmlIssue TrackingVendor Advisory
- https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-NovemIssue TrackingThird Party Advisory
- https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690Issue TrackingThird Party Advisory
- https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-1586Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-15865?
CVE-2017-15865 is a vulnerability with a CVSS score of 7.5 (HIGH). bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE ...
How severe is CVE-2017-15865?
CVE-2017-15865 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15865?
Check the references section above for vendor advisories and patch information. Affected products include: Frrouting Frrouting, Cumulusnetworks Cumulus Linux.