2.9
CVSSv2

CVE-2012-1820

Published: 13/06/2012 Updated: 02/03/2013
CVSS v2 Base Score: 2.9 | Impact Score: 2.9 | Exploitability Score: 5.5
VMScore: 258
Vector: AV:A/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and previous versions allows remote malicious users to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga 0.99.7

quagga quagga 0.99.9

quagga quagga 0.99.6

quagga quagga 0.99.10

quagga quagga 0.98.1

quagga quagga 0.98.2

quagga quagga 0.97.4

quagga quagga 0.97.5

quagga quagga 0.99.20

quagga quagga 0.99.18

quagga quagga 0.99.5

quagga quagga 0.99.8

quagga quagga 0.99.13

quagga quagga 0.99.4

quagga quagga 0.98.5

quagga quagga 0.97.0

quagga quagga 0.97.1

quagga quagga 0.96.2

quagga quagga 0.96.3

quagga quagga 0.99.17

quagga quagga 0.99.11

quagga quagga 0.99.16

quagga quagga 0.99.3

quagga quagga 0.99.15

quagga quagga 0.98.6

quagga quagga 0.98.0

quagga quagga 0.97.2

quagga quagga 0.97.3

quagga quagga 0.96.1

quagga quagga 0.96

quagga quagga 0.95

quagga quagga

quagga quagga 0.99.19

quagga quagga 0.99.1

quagga quagga 0.99.2

quagga quagga 0.99.14

quagga quagga 0.99.12

quagga quagga 0.98.3

quagga quagga 0.98.4

quagga quagga 0.96.5

quagga quagga 0.96.4

Vendor Advisories

Synopsis Moderate: quagga security update Type/Severity Security Advisory: Moderate Topic Updated quagga packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Quagga could be made to crash if it received specially crafted network traffic ...
It was discovered that Quagga, a routing daemon, contains a vulnerability in processing the ORF capability in BGP OPEN messages A malformed OPEN message from a previously configured BGP peer could cause bgpd to crash, causing a denial of service For the stable distribution (squeeze), this problem has been fixed in version 099201-0+squeeze3 Fo ...
Debian Bug report logs - #726724 quagga: CVE-2013-2236 Package: quagga; Maintainer for quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Source for quagga is src:quagga (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 18 Oct 2013 13:03:01 UTC Severity: grave Tags: patch, securit ...
Debian Bug report logs - #730513 CVE-2013-6051 - bgpd crash on valid BGP updates Package: quagga; Maintainer for quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Source for quagga is src:quagga (PTS, buildd, popcon) Reported by: Christian Hammers <ch@debianorg> Date: Mon, 25 Nov 2013 23:54:02 UTC Severity: gr ...
Debian Bug report logs - #676510 CVE-2012-1820: DoS in BGP Package: quagga; Maintainer for quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Source for quagga is src:quagga (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Thu, 7 Jun 2012 13:27:02 UTC Severity: grave Tags: ...
The bgp_capability_orf function in bgpd in Quagga 099201 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message ...