PT-2007-1057 · Quagga+2 · Quagga-Contrib+4

Published

2007-09-12

·

Updated

2017-07-29

·

CVE-2007-4826

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: quagga versions 0.98.3 through 0.98.6 quagga-devel versions 0.98.3 through 0.98.6 quagga-contrib versions 0.98.3 through 0.98.6
Description: The issue affects the quagga package in various operating systems, including CentOS and Red Hat Enterprise Linux. It allows an authenticated attacker to exploit multiple vulnerabilities, potentially leading to a disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely. According to the NVD, bgpd in Quagga before 0.99.9 is vulnerable to a denial of service (crash) via a malformed OPEN message or a COMMUNITY attribute, which triggers a NULL pointer dereference.
Recommendations: For quagga versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. For quagga-devel versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. For quagga-contrib versions 0.98.3 through 0.98.6, consider updating to a version prior to 0.99.9 to mitigate the risk. As a temporary workaround, consider disabling the bgpd service until a patch is available. Restrict access to the quagga package to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06494
BDU:2015-06495
BDU:2015-06497
BDU:2015-06498
BDU:2015-06501
BDU:2015-06502
BDU:2015-08370
BDU:2015-08371
BDU:2015-08372
BDU:2015-08373
BDU:2015-08374
BDU:2015-08375
CVE-2007-4826
DSA-1382-1
RHSA-2010:0785
RHSA-2010_0785

Affected Products

Centos
Red Hat
Quagga
Quagga-Contrib
Quagga-Devel