Labeled Unicast Parsing Vulnerability in FRRouting by FRR
CVE-2023-38407
7.5HIGH
What is CVE-2023-38407?
The FRRouting software before version 8.5 contains a vulnerability within the bgpd/bgp_label.c component, which can lead to a buffer overflow when parsing labeled unicast data. This flaw occurs due to the program attempting to read beyond the end of the data stream, potentially allowing attackers to exploit this weakness and disrupt services or gain unauthorized access. Users are advised to update to the latest version to mitigate any associated risks.