PT-2018-2779 · Quagga+5 · Quagga+5

Published

2018-02-13

·

Updated

2024-09-24

·

CVE-2018-5379

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quagga versions prior to 1.2.3
Description The issue is related to the implementation of the BGP protocol in Quagga software, specifically a double-free memory error when handling certain forms of UPDATE messages that contain cluster-list and/or unknown attributes. This could allow a remote attacker to cause a denial of service or potentially execute arbitrary code.
Recommendations For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the BGP daemon to minimize the risk of exploitation.

Fix

DoS

Double Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1376
BDU:2019-01781
CESA-2018_0377
CVE-2018-5379
DLA-1286-1
DSA-4115-1
MGASA-2018-0133
OPENSUSE-SU-2018_0473-1
OPENSUSE-SU-2024:11290-1
RHSA-2018:0377
RHSA-2018_0377
SUSE-SU-2018:0455-1
SUSE-SU-2018:0456-1
SUSE-SU-2018:0457-1
SUSE-SU-2024:3426-1
USN-3573-1

Affected Products

Alt Linux
Centos
Quagga
Red Hat
Suse
Ubuntu