Skip to main content

Vendor/product archive

quagga / quagga CVEs

Beta · best-effort

33 CVEs tagged to quagga / quagga1 Critical, 9 High, 18 Medium, 5 Low, 0 Unrated.

CVE-2021-44038

Published Nov 19, 2021

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5379

Published Feb 19, 2018

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A su…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2017-16227

Published Oct 29, 2017

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH si…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1245

Published Feb 22, 2017

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5495

Published Jan 24, 2017

All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service of Quagga daemons, or even the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2342

Published Mar 17, 2016

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6051

Published Dec 14, 2013

The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd cra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2236

Published Oct 24, 2013

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line op…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1820

Published Jun 13, 2012

The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BG…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0255

Published Apr 5, 2012

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (asse…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0250

Published Apr 5, 2012

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka L…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0249

Published Apr 5, 2012

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3327

Published Oct 10, 2011

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon cr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3326

Published Oct 10, 2011

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertiseme…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3325

Published Oct 10, 2011

ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a tru…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3324

Published Oct 10, 2011

The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion fa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3323

Published Oct 10, 2011

The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and daemon crash) via a Link State U…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1675

Published Mar 29, 2011

bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1674

Published Mar 29, 2011

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malforme…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2