5
CVSSv2

CVE-2009-1572

Published: 06/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The BGP daemon (bgpd) in Quagga 0.99.11 and previous versions allows remote malicious users to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert error.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga 0.96.3

quagga quagga 0.96.2

quagga quagga 0.99.9

quagga quagga 0.96.4

quagga quagga 0.97.3

quagga quagga 0.97.4

quagga quagga

quagga quagga 0.99.6

quagga quagga 0.98.5

quagga quagga 0.99.3

quagga quagga 0.95

quagga quagga 0.96

quagga quagga 0.97.0

quagga quagga 0.98.1

quagga quagga 0.98.2

quagga quagga 0.99.10

quagga quagga 0.99.8

quagga quagga 0.99.2

quagga quagga 0.96.5

quagga quagga 0.96.1

quagga quagga 0.97.5

quagga quagga 0.98.0

quagga quagga 0.99.4

quagga quagga 0.98.6

quagga quagga 0.99.7

quagga quagga 0.99.5

quagga quagga 0.99.1

quagga quagga 0.97.1

quagga quagga 0.97.2

quagga quagga 0.98.3

quagga quagga 0.98.4

Vendor Advisories

It was discovered that the BGP service in Quagga did not correctly handle certain AS paths containing 4-byte ASNs An authenticated remote attacker could exploit this flaw to cause bgpd to abort, leading to a denial of service ...