Memory leak in frr - CVE-2019-25074

 

Memory leak in frr - CVE-2019-25074

Published: September 13, 2022


Vulnerability identifier: #VU67275
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-25074
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when processing IS-IS HELLO packets. A remote attacker can send specially crafted packets to the IS-IS daemon, trigger memory leak and perform denial of service attack.


Affected software

frr
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
libfrrfpm_pb0-debuginfo
libmlag_pb0-debuginfo
libmlag_pb0
libfrrzmq0-debuginfo
libfrrzmq0
libfrrsnmp0-debuginfo
libfrrsnmp0
libfrrospfapiclient0-debuginfo
libfrrospfapiclient0
libfrrgrpc_pb0-debuginfo
libfrrgrpc_pb0
frr
libfrrfpm_pb0
libfrrcares0-debuginfo
libfrrcares0
libfrr_pb0-debuginfo
libfrr_pb0
libfrr0-debuginfo
libfrr0
frr-devel
frr-debugsource
frr-debuginfo

How to mitigate CVE-2019-25074

Install updates from vendor's website.

frr - update to 8.3.1
libfrrfpm_pb0-debuginfo - update to 7.4-150300.4.7.1
libmlag_pb0-debuginfo - update to 7.4-150300.4.7.1
libmlag_pb0 - update to 7.4-150300.4.7.1
libfrrzmq0-debuginfo - update to 7.4-150300.4.7.1
libfrrzmq0 - update to 7.4-150300.4.7.1
libfrrsnmp0-debuginfo - update to 7.4-150300.4.7.1
libfrrsnmp0 - update to 7.4-150300.4.7.1
libfrrospfapiclient0-debuginfo - update to 7.4-150300.4.7.1
libfrrospfapiclient0 - update to 7.4-150300.4.7.1
libfrrgrpc_pb0-debuginfo - update to 7.4-150300.4.7.1
libfrrgrpc_pb0 - update to 7.4-150300.4.7.1
frr - update to 7.4-150300.4.7.1
libfrrfpm_pb0 - update to 7.4-150300.4.7.1
libfrrcares0-debuginfo - update to 7.4-150300.4.7.1
libfrrcares0 - update to 7.4-150300.4.7.1
libfrr_pb0-debuginfo - update to 7.4-150300.4.7.1
libfrr_pb0 - update to 7.4-150300.4.7.1
libfrr0-debuginfo - update to 7.4-150300.4.7.1
libfrr0 - update to 7.4-150300.4.7.1
frr-devel - update to 7.4-150300.4.7.1
frr-debugsource - update to 7.4-150300.4.7.1
frr-debuginfo - update to 7.4-150300.4.7.1

External References

Related Security Bulletins