Quagga
Quagga: vulnerabilidades y CVE
Quagga tiene 33 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-44038 | Alta (7.8) | 0.79% | — | 19 nov 2021 | An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon… |
| CVE-2012-5521 | Media (6.5) | 1.5% | — | 25 nov 2019 | quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal |
| CVE-2017-3224 | Alta (8.2) | 1.1% | — | 24 jul 2018 | Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same… |
| CVE-2018-5381 | Alta (7.5) | 30% | — | 19 feb 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on… |
| CVE-2018-5380 | Media (4.3) | 15% | — | 19 feb 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input. |
| CVE-2018-5379 | Crítica (9.8) | 38% | — | 19 feb 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of… |
| CVE-2018-5378 | Media (5.9) | 74% | — | 19 feb 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the… |
| CVE-2017-16227 | Alta (7.5) | 19% | — | 29 oct 2017 | The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts… |
| CVE-2016-1245 | Crítica (9.8) | 3.7% | — | 22 feb 2017 | It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible… |
| CVE-2017-5495 | Alta (7.5) | 19% | — | 24 ene 2017 | All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service of Quagga daemons, or even the entire host. When Quagga daemons are… |
| CVE-2016-4049 | Alta (7.5) | 4.6% | — | 23 may 2016 | The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a… |
| CVE-2016-2342 | Alta (8.1) | 12% | — | 17 mar 2016 | The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during… |
| CVE-2013-6051 | Media (4.3) | 2.2% | — | 14 dic 2013 | The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update. |
| CVE-2013-2236 | Baja (2.6) | 2.1% | — | 24 oct 2013 | Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers… |
| CVE-2012-1820 | Baja (2.9) | 1.1% | — | 13 jun 2012 | The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a… |
| CVE-2012-0255 | Media (5) | 3.5% | — | 5 abr 2012 | The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a… |
| CVE-2012-0250 | Baja (3.3) | 1.3% | — | 5 abr 2012 | Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a… |
| CVE-2012-0249 | Baja (3.3) | 1.8% | — | 5 abr 2012 | Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon… |
| CVE-2011-3327 | Alta (7.5) | 7.6% | — | 10 oct 2011 | Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code… |
| CVE-2011-3326 | Media (5) | 4.6% | — | 10 oct 2011 | The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State… |
| CVE-2011-3325 | Media (5) | 4.6% | — | 10 oct 2011 | ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a truncated IPv4 Hello packet. |
| CVE-2011-3324 | Media (5) | 4.7% | — | 10 oct 2011 | The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via trailing zero… |
| CVE-2011-3323 | Media (5) | 4.7% | — | 10 oct 2011 | The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and daemon crash) via a Link State Update message with an invalid IPv6… |
| CVE-2010-1675 | Media (5) | 3.4% | — | 29 mar 2011 | bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute. |
| CVE-2010-1674 | Media (5) | 13% | — | 29 mar 2011 | The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute. |
| CVE-2010-2949 | Media (5) | 3.4% | — | 10 sept 2010 | bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a… |
| CVE-2010-2948 | Media (6.5) | 4.0% | — | 10 sept 2010 | Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute… |
| CVE-2009-1572 | Media (5) | 3.5% | — | 6 may 2009 | The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers… |
| CVE-2007-4826 | Baja (3.5) | 1.7% | — | 12 sept 2007 | bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE:… |
| CVE-2007-1995 | Media (6.3) | 1.7% | — | 12 abr 2007 | bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of… |