5
CVSSv2

CVE-2010-1675

Published: 29/03/2011 Updated: 06/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

bgpd in Quagga prior to 0.99.18 allows remote malicious users to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga 0.99.10

quagga quagga 0.96.3

quagga quagga 0.96.2

quagga quagga 0.95

quagga quagga 0.99.7

quagga quagga 0.99.11

quagga quagga 0.96.1

quagga quagga 0.96

quagga quagga 0.98.0

quagga quagga 0.98.1

quagga quagga 0.98.5

quagga quagga 0.99.12

quagga quagga 0.99.2

quagga quagga 0.99.15

quagga quagga 0.99.1

quagga quagga 0.99.9

quagga quagga 0.97.2

quagga quagga 0.97.3

quagga quagga 0.98.4

quagga quagga 0.99.14

quagga quagga 0.99.6

quagga quagga 0.99.13

quagga quagga 0.99.8

quagga quagga

quagga quagga 0.99.5

quagga quagga 0.97.0

quagga quagga 0.97.1

quagga quagga 0.98.2

quagga quagga 0.98.3

quagga quagga 0.99.4

quagga quagga 0.98.6

quagga quagga 0.99.3

quagga quagga 0.99.16

quagga quagga 0.96.4

quagga quagga 0.96.5

quagga quagga 0.97.4

quagga quagga 0.97.5

Vendor Advisories

An attacker could send crafted input to Quagga and cause it to crash ...
It has been discovered that the Quagga routing daemon contains two denial-of-service vulnerabilities in its BGP implementation: CVE-2010-1674 A crafted Extended Communities attribute triggers a NULL pointer dereference which causes the BGP daemon to crash The crafted attributes are not propagated by the Internet core, so only expl ...