Lucene search

K
ubuntuUbuntuUSN-512-1
HistorySep 15, 2007 - 12:00 a.m.

Quagga vulnerability

2007-09-1500:00:00
ubuntu.com
33

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.9%

Releases

  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06

Packages

  • quagga -

Details

It was discovered that Quagga did not correctly verify OPEN messages or
COMMUNITY attributes sent from configured peers. Malicious authenticated
remote peers could send a specially crafted message which would cause
bgpd to abort, leading to a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu7.04noarchquagga< 0.99.6-2ubuntu3.2UNKNOWN
Ubuntu6.10noarchquagga< 0.99.4-4ubuntu1.2UNKNOWN
Ubuntu6.06noarchquagga< 0.99.2-1ubuntu3.3UNKNOWN

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.9%