UbuntuUpdates.org

Package "frr-pythontools"

Name: frr-pythontools

Description:

FRRouting suite - Python tools

Latest version: 8.1-1ubuntu1.13
Release: jammy (22.04)
Level: updates
Repository: main
Head package: frr
Homepage: https://www.frrouting.org/

Links


Download "frr-pythontools"


Other versions of "frr-pythontools" in Jammy

Repository Area Version
base main 8.1-1ubuntu1
security main 8.1-1ubuntu1.13

Changelog

Version: 8.1-1ubuntu1.7 2023-11-15 17:08:48 UTC

  frr (8.1-1ubuntu1.7) jammy-security; urgency=medium

  * SECURITY UPDATE: DoS via MP_REACH_NLRI data
    - debian/patches/CVE-2023-46752.patch: handle MP_REACH_NLRI malformed
      packets with session reset in bgpd/bgp_attr.c, bgpd/bgp_attr.h,
      bgpd/bgp_packet.c.
    - CVE-2023-46752
  * SECURITY UPDATE: DoS via BGP UPDATE without mandatory attributes
    - debian/patches/CVE-2023-46753.patch: check mandatory attributes more
      carefully for UPDATE message in bgpd/bgp_attr.c.
    - CVE-2023-46753

 -- Marc Deslauriers <email address hidden> Wed, 01 Nov 2023 14:30:38 -0400

Source diff to previous version
CVE-2023-46752 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVE-2023-46753 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one wi

Version: 8.1-1ubuntu1.6 2023-10-18 06:07:03 UTC

  frr (8.1-1ubuntu1.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2023-41358.patch: Do not process NLRIs if the
      attribute length is zero
    - debian/patches/CVE-2023-41360.patch: Don't read the first byte of ORF
      header if we are ahead of stream
    - CVE-2023-41358
    - CVE-2023-41360
  * SECURITY UPDATE: Null pointer dereference
    - debian/patches/CVE-2023-41909.patch: Limit flowspec to no attribute
      means a implicit withdrawal
    - CVE-2023-41909

 -- Nishit Majithia <email address hidden> Mon, 16 Oct 2023 13:03:51 +0530

Source diff to previous version
CVE-2023-41358 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
CVE-2023-41360 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
CVE-2023-41909 An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes,

Version: 8.1-1ubuntu1.5 2023-08-31 04:07:09 UTC

  frr (8.1-1ubuntu1.5) jammy-security; urgency=medium

  * SECURITY UPDATE: a BGP route attribute, tunnel encapsulation, can
    be corrupted and cause denial of service
    - debian/patches/CVE-2023-38802.patch: use treat-as-withdraw for
      tunnel encapsulation attribute
    - CVE-2023-31490

 -- Mark Esler <email address hidden> Wed, 30 Aug 2023 10:39:00 -0500

Source diff to previous version
CVE-2023-38802 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupte
CVE-2023-31490 An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

Version: 8.1-1ubuntu1.4 2023-06-05 16:07:23 UTC

  frr (8.1-1ubuntu1.4) jammy-security; urgency=medium

  * SECURITY UPDATE: denial of service via bgp_attr_psid_sub()
    - debian/patches/CVE-2023-31490.patch: ensure stream received has
      enough data in bgpd/bgp_attr.c.
    - CVE-2023-31490

 -- Marc Deslauriers <email address hidden> Fri, 02 Jun 2023 13:56:18 -0400

Source diff to previous version
CVE-2023-31490 An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

Version: 8.1-1ubuntu1.3 2022-12-13 02:06:20 UTC

  frr (8.1-1ubuntu1.3) jammy; urgency=medium

  * d/frr.postinst: don't change log ownership if the syslog user
    doesn't exist. Thanks to Alessandro Ratti
    <email address hidden> for the fix (LP: #1991812).

 -- Andreas Hasenack <email address hidden> Fri, 28 Oct 2022 11:38:34 -0300

1991812 FRR deb packaging regression



About   -   Send Feedback to @ubuntu_updates