cvelist/2017/15xxx/CVE-2017-15865.json
2019-03-18 04:34:41 +00:00

82 lines
3.1 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2017-15865",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492)."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-November/000009.html",
"refsource": "CONFIRM",
"url": "https://lists.cumulusnetworks.com/pipermail/cumulus-security-announce/2017-November/000009.html"
},
{
"name": "https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-15865-Malformed-BGP-UPDATE-Triggers-Information-Disclosure",
"refsource": "CONFIRM",
"url": "https://support.cumulusnetworks.com/hc/en-us/articles/115014778107-CVE-2017-15865-Malformed-BGP-UPDATE-Triggers-Information-Disclosure"
},
{
"name": "https://frrouting.org/community/security.html",
"refsource": "CONFIRM",
"url": "https://frrouting.org/community/security.html"
},
{
"name": "101794",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/101794"
},
{
"name": "https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690",
"refsource": "CONFIRM",
"url": "https://support.cumulusnetworks.com/hc/en-us/articles/115014754307#rn690"
}
]
}
}