<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:37:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5194 — Important: frr security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: frr, AlmaLinux:9: frr-selinux&lt;/p&gt;
&lt;p&gt;FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router (CVE-2023-38802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: frr, AlmaLinux:9: frr-selinux&lt;/p&gt;
&lt;p&gt;FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router (CVE-2023-38802)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5194</guid>
    </item>
    <item>
      <title>bdu:2023-05649</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05649</link>
      <description>bdu:2023-05649</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05649</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0746 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Palo Alto Networks&lt;/span&gt;. Certa…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0746</link>
      <description>certfr-2023-avi-0746</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0746</guid>
    </item>
    <item>
      <title>EUVD-2026-190919</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-190919</link>
      <description>EUVD-2026-190919</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-190919</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38802</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38802</link>
      <description>&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38802</guid>
    </item>
    <item>
      <title>GHSA-xh4f-v933-c556</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xh4f-v933-c556</link>
      <description>&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xh4f-v933-c556</guid>
    </item>
    <item>
      <title>gsd-2023-38802</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38802</link>
      <description>gsd-2023-38802</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38802</guid>
    </item>
    <item>
      <title>ICSA-24-102-04 — Siemens RUGGEDCOM APE1808</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-102-04</link>
      <description>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-102-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-38802 — FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a craf…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-38802</link>
      <description>msrc_CVE-2023-38802</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-38802</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13191-1 — frr-8.4-5.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13191-1</link>
      <description>&lt;p&gt;frr-8.4-5.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;frr-8.4-5.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13191-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5195 — Red Hat Security Advisory: frr security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5195</link>
      <description>&lt;p&gt;frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5195</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3709-1 — Security update for frr</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3709-1</link>
      <description>&lt;p&gt;Security update for frr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for frr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3709-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-38802</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: frr, Ubuntu:22.04:LTS: frr&lt;/p&gt;
&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: frr, Ubuntu:22.04:LTS: frr&lt;/p&gt;
&lt;p&gt;FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38802</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2205 — FRRouting Project FRRouting: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2205</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FRRouting Project FRRouting ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FRRouting Project FRRouting ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2205</guid>
    </item>
  </channel>
</rss>
