6.5
CVSSv2

CVE-2010-2948

Published: 10/09/2010 Updated: 13/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga prior to 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga 0.99.11

quagga quagga 0.99.2

quagga quagga 0.97.5

quagga quagga 0.95

quagga quagga 0.98.3

quagga quagga 0.96.3

quagga quagga 0.99.4

quagga quagga 0.99.7

quagga quagga 0.99.14

quagga quagga 0.99.5

quagga quagga 0.96.5

quagga quagga 0.98.0

quagga quagga

quagga quagga 0.96.1

quagga quagga 0.98.1

quagga quagga 0.96.4

quagga quagga 0.98.5

quagga quagga 0.97.3

quagga quagga 0.99.3

quagga quagga 0.99.13

quagga quagga 0.99.6

quagga quagga 0.98.6

quagga quagga 0.97.4

quagga quagga 0.98.4

quagga quagga 0.99.12

quagga quagga 0.98.2

quagga quagga 0.97.1

quagga quagga 0.97.0

quagga quagga 0.96.2

quagga quagga 0.99.9

quagga quagga 0.99.1

quagga quagga 0.97.2

quagga quagga 0.99.15

quagga quagga 0.99.10

quagga quagga 0.99.8

quagga quagga 0.96

Vendor Advisories

Synopsis Moderate: quagga security update Type/Severity Security Advisory: Moderate Topic Updated quagga packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 4 and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnera ...
Debian Bug report logs - #594262 quagga: Two BGP security problems fixed in 09917 Package: quagga; Maintainer for quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Source for quagga is src:quagga (PTS, buildd, popcon) Reported by: Christian Hammers <ch@debianorg> Date: Tue, 24 Aug 2010 23:21:02 UTC Severity: ...
It was discovered that Quagga incorrectly handled certain Outbound Route Filtering (ORF) records A remote authenticated attacker could use this flaw to cause a denial of service or potentially execute arbitrary code The default compiler options for Ubuntu 804 LTS and later should reduce the vulnerability to a denial of service (CVE-2010-2948) ...