CVE-2007-1995
CVE-2007-1995
bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugzilla.quagga.net/show_bug.cgi?id=354http://bugzilla.quagga.net/show_bug.cgi?id=355http://secunia.com/advisories/24808http://secunia.com/advisories/25084http://secunia.com/advisories/25119http://secunia.com/advisories/25255http://secunia.com/advisories/25293http://secunia.com/advisories/25312http://secunia.com/advisories/25428http://secunia.com/advisories/29743http://security.gentoo.org/glsa/glsa-200705-05.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/33547