An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
History

Thu, 08 May 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Osrg
Osrg gobgp
CPEs cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
Vendors & Products Osrg
Osrg gobgp

Mon, 21 Apr 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 01:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g.. by ensuring that there are 12 bytes or 36 bytes (depending on the address family). An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


Mon, 21 Apr 2025 01:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g.. by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-21T00:00:00.000Z

Updated: 2025-04-21T01:56:11.101Z

Reserved: 2025-04-21T00:00:00.000Z

Link: CVE-2025-43970

cve-icon Vulnrichment

Updated: 2025-04-21T01:56:04.334Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-21T01:15:45.310

Modified: 2025-05-08T15:45:51.090

Link: CVE-2025-43970

cve-icon Redhat

No data.