PT-2006-1051 · Quagga+1 · Quagga+1

Konstantin V. Gavrilenko

·

Publicado

2006-05-05

·

Atualizado

2024-06-15

·

CVE-2006-2223

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Quagga versions 0.98 and 0.99 before 20060503 Quagga versions prior to 0.98.6-r1
Description: The issue concerns the improper implementation of configurations in RIPd, specifically regarding the disabling of RIPv1 or the requirement of plaintext or MD5 authentication. This allows remote attackers to obtain sensitive routing state information via REQUEST packets, such as SEND UPDATE. Multiple vulnerabilities in the Quagga package can lead to a breach of protected information, and exploitation can be carried out remotely.
Recommendations: For Quagga versions 0.98 and 0.99 before 20060503, update to a version after 20060503 to resolve the issue. For Quagga versions prior to 0.98.6-r1, update to version 0.98.6-r1 or later to fix the vulnerabilities. As a temporary workaround, consider restricting access to the RIPd configuration to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09507
CVE-2006-2223
DSA-1059-1
OPENSUSE-SU-2024:11290-1
RHSA-2006:0525
RHSA-2006_0525

Produtos afetados

Quagga
Red Hat