3.5
CVSSv2

CVE-2007-4826

Published: 12/09/2007 Updated: 29/07/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

bgpd in Quagga prior to 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is enabled.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga 0.96.2

quagga quagga 0.99.2

quagga quagga 0.96.5

quagga quagga 0.96.1

quagga quagga 0.97.5

quagga quagga 0.98.0

quagga quagga 0.99.6

quagga quagga 0.98.5

quagga quagga 0.99.4

quagga quagga 0.99.7

quagga quagga 0.99.5

quagga quagga 0.97.1

quagga quagga 0.97.2

quagga quagga 0.98.3

quagga quagga 0.98.4

quagga quagga

quagga quagga 0.99.3

quagga quagga 0.95

quagga quagga 0.96

quagga quagga 0.97.0

quagga quagga 0.98.1

quagga quagga 0.98.2

quagga quagga 0.98.6

quagga quagga 0.96.3

quagga quagga 0.99.1

quagga quagga 0.96.4

quagga quagga 0.97.3

quagga quagga 0.97.4

Vendor Advisories

Synopsis Moderate: quagga security update Type/Severity Security Advisory: Moderate Topic Updated quagga packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 4 and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnera ...
Debian Bug report logs - #442133 CVE-2007-4826 remote denial of service Package: quagga; Maintainer for quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Source for quagga is src:quagga (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 13 Sep 2007 12:51:03 UTC Severity: normal Tags: sec ...
It was discovered that Quagga did not correctly verify OPEN messages or COMMUNITY attributes sent from configured peers Malicious authenticated remote peers could send a specially crafted message which would cause bgpd to abort, leading to a denial of service ...