Lucene search

K
cve[email protected]CVE-2012-0255
HistoryApr 05, 2012 - 1:25 p.m.

CVE-2012-0255

2012-04-0513:25:30
CWE-119
web.nvd.nist.gov
53
quagga
bgpd
denial of service
vulnerability
as4 capability
cve-2012-0255

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).

Affected configurations

NVD
Node
quaggaquaggaRange0.99.20
OR
quaggaquaggaMatch0.95
OR
quaggaquaggaMatch0.96
OR
quaggaquaggaMatch0.96.1
OR
quaggaquaggaMatch0.96.2
OR
quaggaquaggaMatch0.96.3
OR
quaggaquaggaMatch0.96.4
OR
quaggaquaggaMatch0.96.5
OR
quaggaquaggaMatch0.97.0
OR
quaggaquaggaMatch0.97.1
OR
quaggaquaggaMatch0.97.2
OR
quaggaquaggaMatch0.97.3
OR
quaggaquaggaMatch0.97.4
OR
quaggaquaggaMatch0.97.5
OR
quaggaquaggaMatch0.98.0
OR
quaggaquaggaMatch0.98.1
OR
quaggaquaggaMatch0.98.2
OR
quaggaquaggaMatch0.98.3
OR
quaggaquaggaMatch0.98.4
OR
quaggaquaggaMatch0.98.5
OR
quaggaquaggaMatch0.98.6
OR
quaggaquaggaMatch0.99.1
OR
quaggaquaggaMatch0.99.2
OR
quaggaquaggaMatch0.99.3
OR
quaggaquaggaMatch0.99.4
OR
quaggaquaggaMatch0.99.5
OR
quaggaquaggaMatch0.99.6
OR
quaggaquaggaMatch0.99.7
OR
quaggaquaggaMatch0.99.8
OR
quaggaquaggaMatch0.99.9
OR
quaggaquaggaMatch0.99.10
OR
quaggaquaggaMatch0.99.11
OR
quaggaquaggaMatch0.99.12
OR
quaggaquaggaMatch0.99.13
OR
quaggaquaggaMatch0.99.14
OR
quaggaquaggaMatch0.99.15
OR
quaggaquaggaMatch0.99.16
OR
quaggaquaggaMatch0.99.17
OR
quaggaquaggaMatch0.99.18
OR
quaggaquaggaMatch0.99.19

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%