An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Link | Tags |
---|---|
https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 | patch release notes |
https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986 | patch |