Lucene search

K
cve[email protected]CVE-2013-2236
HistoryOct 24, 2013 - 3:48 a.m.

CVE-2013-2236

2013-10-2403:48:46
CWE-119
web.nvd.nist.gov
49
cve-2013-2236
stack-based buffer overflow
ospfd
quagga
denial of service
nvd
vulnerability

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

8.6 High

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

Affected configurations

NVD
Node
quaggaquaggaRange0.99.22.1
OR
quaggaquaggaMatch0.99.22

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

8.6 High

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%