PT-2017-16536 · Quagga+5 · Quagga+5

Carnil

·

Published

2017-01-24

·

Updated

2024-06-15

·

CVE-2017-5495

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Quagga versions 0.93 through 1.1.0
Description The issue is related to an unbounded memory allocation in the telnet 'vty' CLI, which can lead to a Denial-of-Service of Quagga daemons or the entire host. This can be triggered by anyone who can connect to the TCP ports when the Quagga daemons are configured with their telnet CLI enabled, prior to authentication. Most distributions restrict the Quagga telnet interface to local access only by default. The Quagga telnet interface 'vty' input buffer grows automatically without bound as long as a newline is not entered, allowing an attacker to cause the Quagga daemon to allocate unbounded memory by sending very long strings without a newline.
Recommendations For Quagga versions 0.93 through 1.1.0, update to Quagga 1.1.1 or later to resolve the issue. As a temporary workaround, consider disabling the telnet CLI until a patch is available. Restrict access to the telnet interface to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2400
CESA-2017_0794
CVE-2017-5495
MGASA-2017-0071
OPENSUSE-SU-2024:11290-1
RHSA-2017:0794
RHSA-2017_0794
SUSE-SU-2017:2294-1
SUSE-SU-2018:0455-1
SUSE-SU-2018:0457-1
USN-3471-1

Affected Products

Alt Linux
Centos
Quagga
Red Hat
Suse
Ubuntu