Lucene search

K

Quagga Security Vulnerabilities

cve
cve

CVE-2011-3325

ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a truncated IPv4 Hello...

8.9AI Score

0.105EPSS

2011-10-10 10:55 AM
36
cve
cve

CVE-2011-3323

The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and daemon crash) via a Link State Update message with an invalid IPv6 prefix...

8.8AI Score

0.091EPSS

2011-10-10 10:55 AM
42
cve
cve

CVE-2011-3327

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over...

9.7AI Score

0.303EPSS

2011-10-10 10:55 AM
53
cve
cve

CVE-2011-3326

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update...

8.8AI Score

0.091EPSS

2011-10-10 10:55 AM
38
cve
cve

CVE-2013-6051

The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP...

6.3AI Score

0.008EPSS

2013-12-14 05:21 PM
31
cve
cve

CVE-2013-2236

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large...

8.6AI Score

0.053EPSS

2013-10-24 03:48 AM
49
cve
cve

CVE-2011-3324

The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via trailing zero values in the Link State Advertisement (LSA) header list of an IPv6 Database...

8.8AI Score

0.091EPSS

2011-10-10 10:55 AM
43
cve
cve

CVE-2010-2948

Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP...

7.8AI Score

0.056EPSS

2010-09-10 07:00 PM
36
cve
cve

CVE-2010-2949

bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a BGP UPDATE...

6.3AI Score

0.182EPSS

2010-09-10 07:00 PM
41
cve
cve

CVE-2021-44038

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-11-19 07:15 PM
169
cve
cve

CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes...

6.5CVSS

6.4AI Score

0.004EPSS

2019-11-25 02:15 PM
29
cve
cve

CVE-2017-3224

Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then...

8.2CVSS

5.6AI Score

0.001EPSS

2018-07-24 03:29 PM
36
cve
cve

CVE-2018-5378

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may...

7.1CVSS

7.2AI Score

0.575EPSS

2018-02-19 01:29 PM
60
cve
cve

CVE-2018-5380

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on...

4.3CVSS

6.5AI Score

0.005EPSS

2018-02-19 01:29 PM
60
cve
cve

CVE-2018-5381

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized...

7.5CVSS

8.1AI Score

0.122EPSS

2018-02-19 01:29 PM
64
cve
cve

CVE-2018-5379

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary...

9.8CVSS

9.5AI Score

0.056EPSS

2018-02-19 01:29 PM
100
cve
cve

CVE-2017-16227

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid...

7.5CVSS

7.2AI Score

0.011EPSS

2017-10-29 08:29 PM
77
cve
cve

CVE-2016-1245

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is...

9.8CVSS

8.8AI Score

0.026EPSS

2017-02-22 11:59 PM
50
cve
cve

CVE-2017-5495

All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service of Quagga daemons, or even the entire host. When Quagga daemons are configured with their telnet CLI enabled, anyone who can connect to the TCP ports....

7.5CVSS

7.3AI Score

0.268EPSS

2017-01-24 07:59 AM
82
4
cve
cve

CVE-2016-4049

The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP...

7.5CVSS

7.2AI Score

0.026EPSS

2016-05-23 07:59 PM
39
cve
cve

CVE-2016-2342

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remote attackers to execute arbitrary code or cause.....

8.1CVSS

8.2AI Score

0.014EPSS

2016-03-17 02:59 PM
52
cve
cve

CVE-2012-1820

The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN...

5.9AI Score

0.011EPSS

2012-06-13 03:55 PM
49
cve
cve

CVE-2012-0255

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4...

6AI Score

0.028EPSS

2012-04-05 01:25 PM
53
cve
cve

CVE-2012-0249

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the...

6.1AI Score

0.015EPSS

2012-04-05 01:25 PM
45
cve
cve

CVE-2012-0250

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than.....

6.1AI Score

0.023EPSS

2012-04-05 01:25 PM
43
cve
cve

CVE-2010-1675

bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path...

6.2AI Score

0.104EPSS

2011-03-29 06:55 PM
38
cve
cve

CVE-2010-1674

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities...

6.2AI Score

0.169EPSS

2011-03-29 06:55 PM
37
cve
cve

CVE-2009-1572

The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert...

7.1AI Score

0.109EPSS

2009-05-06 05:30 PM
24
cve
cve

CVE-2007-4826

bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is...

6AI Score

0.006EPSS

2007-09-12 10:17 AM
31
cve
cve

CVE-2007-1995

bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an...

6.2AI Score

0.025EPSS

2007-04-12 10:19 AM
26
cve
cve

CVE-2006-2276

bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to cause a denial of service (CPU consumption) via a certain sh ip bgp command entered in the telnet...

5.9AI Score

0.079EPSS

2006-05-10 02:14 AM
39
cve
cve

CVE-2006-2223

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND...

5.9AI Score

0.017EPSS

2006-05-05 07:02 PM
24
cve
cve

CVE-2006-2224

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE...

6.4AI Score

0.125EPSS

2006-05-05 07:02 PM
30
cve
cve

CVE-2003-0795

The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null....

6.2AI Score

0.018EPSS

2003-12-15 05:00 AM
21
cve
cve

CVE-2003-0858

Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink...

5.7AI Score

0.0004EPSS

2003-12-15 05:00 AM
24
cve
cve

CVE-2003-0859

The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink...

6AI Score

0.0004EPSS

2003-12-15 05:00 AM
28