PT-2007-1057 · Quagga+2 · Quagga-Contrib+4

Publicado

2007-09-12

·

Atualizado

2017-07-29

·

CVE-2007-4826

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: quagga versions 0.98.3 through 0.98.6 quagga-devel versions 0.98.3 through 0.98.6 quagga-contrib versions 0.98.3 through 0.98.6
Description: The issue affects the quagga package in various operating systems, including CentOS and Red Hat Enterprise Linux. It allows an authenticated attacker to exploit multiple vulnerabilities, potentially leading to a disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely. According to the NVD, bgpd in Quagga before 0.99.9 is vulnerable to a denial of service (crash) via a malformed OPEN message or a COMMUNITY attribute, which triggers a NULL pointer dereference.
Recommendations: For quagga versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. For quagga-devel versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. For quagga-contrib versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. As a temporary workaround, consider disabling the bgpd service until a patch is available. Restrict access to the quagga package to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-06494
BDU:2015-06495
BDU:2015-06497
BDU:2015-06498
BDU:2015-06501
BDU:2015-06502
BDU:2015-08370
BDU:2015-08371
BDU:2015-08372
BDU:2015-08373
BDU:2015-08374
BDU:2015-08375
CVE-2007-4826
DSA-1382-1
RHSA-2010:0785
RHSA-2010_0785

Produtos afetados

Centos
Red Hat
Quagga
Quagga-Contrib
Quagga-Devel