CVE-2007-1995
Published Apr 12, 2007
Last updated 7 years ago
Overview
- Description
- bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.3
- Impact score
- 6.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4390D804-1FBF-4A25-8E44-9598A11657CA", "versionEndIncluding": "0.98.6" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD7A8AD5-A315-4242-960C-05E792B30547" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B83BCE2-24D0-4B5B-A034-62BFF1894AE2" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDD63DD9-1809-4CEC-AB69-955A7B127CA8" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A2AD1AD-DDE2-477B-8EFD-767B6FD8EDBB" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99BD881B-9B53-4E12-B083-87C9C87CDF62" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F910313F-FFE1-470A-A9B6-8A854C73DC97" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B0A9232-968D-4D3E-82A0-F5CC858EAF48" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD5F4CFB-BE1F-4424-8D2F-B921704E3AA0" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A55FF13-8E56-4A27-B7FD-A855735E1045" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7DDBC3B-99BB-4404-9A73-90ED6581D69A" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB09A713-E91E-44E7-8B82-F70F655A97B1" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10173750-690B-4576-AB3F-11A0861AA78B" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EF8693A-D561-4D2E-BD60-5630601C6A94" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE43983A-73CB-41A5-889B-1AEA9A27F440" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6EB589E9-85C0-4E87-856B-A2832383B129" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CF5EB8A-8E46-4490-BA88-03D4BED3EB84" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C6445BEF-245C-47CE-9779-96C97CFD4DA7" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48D007FD-C1AD-477E-9AA5-DDB4522D3248" }, { "criteria": "cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6ADB9F6-B519-45D0-966F-F095372FBB49" } ], "operator": "OR" } ] } ]