PT-2006-1051 · Quagga+1 · Quagga+1

Konstantin V. Gavrilenko

·

Published

2006-05-05

·

Updated

2024-06-15

·

CVE-2006-2223

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Quagga versions 0.98 and 0.99 before 20060503 Quagga versions prior to 0.98.6-r1
Description: The issue concerns the improper implementation of configurations in RIPd, specifically regarding the disabling of RIPv1 or the requirement of plaintext or MD5 authentication. This allows remote attackers to obtain sensitive routing state information via REQUEST packets, such as SEND UPDATE. Multiple vulnerabilities in the Quagga package can lead to a breach of protected information, and exploitation can be carried out remotely.
Recommendations: For Quagga versions 0.98 and 0.99 before 20060503, update to a version after 20060503 to resolve the issue. For Quagga versions prior to 0.98.6-r1, update to version 0.98.6-r1 or later to fix the vulnerabilities. As a temporary workaround, consider restricting access to the RIPd configuration to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09507
CVE-2006-2223
DSA-1059-1
OPENSUSE-SU-2024:11290-1
RHSA-2006:0525
RHSA-2006_0525

Affected Products

Quagga
Red Hat