SUSE SLES15 / openSUSE 15 Security Update : frr (SUSE-SU-2024:4090-1)

critical Nessus Plugin ID 212585

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2024:4090-1 advisory.

Update to frr 8.5.6 (jsc#PED-PED-11092) including fixes for:

- CVE-2024-44070,CVE-2024-34088,CVE-2024-31951,CVE-2024-31950, CVE-2024-31948,CVE-2024-27913,CVE-2023-47235,CVE-2023-47234, CVE-2023-46753,CVE-2023-46752,CVE-2023-41909,CVE-2023-41360, CVE-2023-41358,CVE-2023-38802,CVE-2023-38407,CVE-2023-38406, CVE-2023-3748,CVE-2023-31490,CVE-2023-31489 and other bugfixes.
See https://frrouting.org/release/8.5.6/ for details.

The most recent frr 8.x series provides several new features, improvements and bug fixes for various protocols and daemons, especially for PIM/PIMv6/BGP and VRF support.

See https://frrouting.org/release/8.5/ for details and links.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://www.suse.com/security/cve/CVE-2023-31489

https://www.suse.com/security/cve/CVE-2023-31490

https://www.suse.com/security/cve/CVE-2023-3748

https://www.suse.com/security/cve/CVE-2023-38802

https://www.suse.com/security/cve/CVE-2023-41358

https://www.suse.com/security/cve/CVE-2023-41360

https://www.suse.com/security/cve/CVE-2023-41909

https://www.suse.com/security/cve/CVE-2023-46752

https://www.suse.com/security/cve/CVE-2023-46753

https://www.suse.com/security/cve/CVE-2023-38406

https://www.suse.com/security/cve/CVE-2023-38407

https://www.suse.com/security/cve/CVE-2023-47234

https://www.suse.com/security/cve/CVE-2023-47235

https://www.suse.com/security/cve/CVE-2024-27913

https://www.suse.com/security/cve/CVE-2024-31948

https://www.suse.com/security/cve/CVE-2024-31950

https://www.suse.com/security/cve/CVE-2024-31951

https://www.suse.com/security/cve/CVE-2024-34088

https://www.suse.com/security/cve/CVE-2024-44070

http://www.nessus.org/u?3cbaaa18

Plugin Details

Severity: Critical

ID: 212585

File Name: suse_SU-2024-4090-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 12/12/2024

Updated: 12/12/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-38406

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:frr, p-cpe:/a:novell:suse_linux:libfrrzmq0, p-cpe:/a:novell:suse_linux:libfrrospfapiclient0, p-cpe:/a:novell:suse_linux:libfrr0, p-cpe:/a:novell:suse_linux:libfrrsnmp0, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:frr-devel, p-cpe:/a:novell:suse_linux:libfrrfpm_pb0, p-cpe:/a:novell:suse_linux:libmlag_pb0, p-cpe:/a:novell:suse_linux:libfrr_pb0, p-cpe:/a:novell:suse_linux:libfrrcares0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/28/2024

Vulnerability Publication Date: 5/9/2023

Reference Information

CVE: CVE-2023-31489, CVE-2023-31490, CVE-2023-3748, CVE-2023-38406, CVE-2023-38407, CVE-2023-38802, CVE-2023-41358, CVE-2023-41360, CVE-2023-41909, CVE-2023-46752, CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-27913, CVE-2024-31948, CVE-2024-31950, CVE-2024-31951, CVE-2024-34088, CVE-2024-44070

SuSE: SUSE-SU-2024:4090-1