PT-2007-1057 · Quagga+2 · Quagga-Contrib+4
Publicado
2007-09-12
·
Atualizado
2017-07-29
·
CVE-2007-4826
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
quagga versions 0.98.3 through 0.98.6
quagga-devel versions 0.98.3 through 0.98.6
quagga-contrib versions 0.98.3 through 0.98.6
Description:
The issue affects the quagga package in various operating systems, including CentOS and Red Hat Enterprise Linux. It allows an authenticated attacker to exploit multiple vulnerabilities, potentially leading to a disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely. According to the NVD, bgpd in Quagga before 0.99.9 is vulnerable to a denial of service (crash) via a malformed OPEN message or a COMMUNITY attribute, which triggers a NULL pointer dereference.
Recommendations:
For quagga versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk.
For quagga-devel versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk.
For quagga-contrib versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk.
As a temporary workaround, consider disabling the bgpd service until a patch is available.
Restrict access to the quagga package to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Quagga
Quagga-Contrib
Quagga-Devel