PT-2011-5217 · Quagga+2 · Quagga+2
Jukka Taimisto
+2
·
Published
1970-01-01
·
Updated
2018-01-06
·
CVE-2011-3324
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Quagga versions prior to 0.99.19
Quagga version 0.99.15
Description
The issue allows remote attackers to cause a denial of service via trailing zero values in the Link State Advertisement (LSA) header list of an IPv6 Database Description message. This is due to the
ospf6 lsa is changed function in ospf6 lsa.c in the OSPFv3 implementation in ospf6d. The vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information.Recommendations
For Quagga versions prior to 0.99.19, update to version 0.99.19 or later to resolve the issue.
For Quagga version 0.99.15, update to version 0.99.19 or later to resolve the issue.
As a temporary workaround, consider disabling the
ospf6 lsa is changed function until a patch is available.
Restrict access to the ospf6d module to minimize the risk of exploitation.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Quagga
Red Hat