PT-2011-5218 · Quagga+2 · Quagga+2
Publicado
1970-01-01
·
Atualizado
2018-01-06
·
CVE-2011-3325
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Quagga versions prior to 0.99.19
Quagga version 0.99.15
Description
The issue concerns multiple vulnerabilities in the Quagga package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the
ospf packet.c file in ospfd allows remote attackers to cause a denial of service (daemon crash) via a 0x0a type field in an IPv4 packet header or a truncated IPv4 Hello packet.Recommendations
For Quagga versions prior to 0.99.19, update to version 0.99.19 or later to resolve the issue.
For Quagga version 0.99.15, update to version 0.99.19 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
ospfd service to minimize the risk of exploitation.Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Quagga
Red Hat