Logo
vulnerabilityCVE-2023-41910
Name
CVE-2023-41910
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lldpd
Exploitable

Vulnerability Ratings#


9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.0.18
Not Affected
buildroot
master
1.0.20
Not Affected
openwrt
master
1.0.22-r1
Not Affected
openwrt
openwrt-25.12
1.0.20-r1
Not Affected
yocto
master
1.0.22
Not Affected
yocto
scarthgap
1.0.18
Not Affected