The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert error.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade quagga | Dec 10, 2025 | May 6, 2009 |
| Oracle Solaris | — | Upgrade system/network/routing/quagga to version 0.99.19-0.175.0.4.0.2.0 on Solaris 11.0 | May 29, 2017 | May 6, 2009 |
| Suse | — | Upgrade quagga | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade quagga | Nov 8, 2024 | May 6, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub