4.3
CVSSv3

CVE-2018-5380

Published: 19/02/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

Vulnerable Product Search on Vulmon Subscribe to Product

quagga quagga

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

siemens ruggedcom_rox_ii_firmware

Vendor Advisories

Several security issues were fixed in Quagga ...
Debian Bug report logs - #890563 quagga: CVE-2018-5378 CVE-2018-5379 CVE-2018-5380 CVE-2018-5381 Package: src:quagga; Maintainer for src:quagga is Brett Parker <iDunno@sommitrealweirdcouk>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 15 Feb 2018 22:42:05 UTC Severity: serious Tags: fixed-upstre ...
Several vulnerabilities have been discovered in Quagga, a routing daemon The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2018-5378 It was discovered that the Quagga BGP daemon, bgpd, does not properly bounds check data sent with a NOTIFY to a peer, if an attribute length is invalid A configured B ...
Infinite loop issue triggered by invalid OPEN message allows denial-of-serviceAn infinite loop vulnerability was discovered in Quagga A BGP peer could send specially crafted packets that would cause the daemon to enter an infinite loop, denying service and consuming CPU until it is restarted(CVE-2018-5381) Double free vulnerability in bgpd when p ...
A vulnerability was found in Quagga, in the log formatting code Specially crafted messages sent by BGP peers could cause Quagga to read one element past the end of certain static arrays, causing arbitrary binary data to appear in the logs or potentially, a crash ...