ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a truncated IPv4 Hello packet.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade quaggaUpgrade quagga-contribUpgrade quagga-devel | Dec 1, 2016 | Oct 10, 2011 |
| Freebsd | — | Upgrade quagga | Dec 10, 2025 | Oct 5, 2011 |
| Gentoo Linux | — | Upgrade net-misc/quagga. | Oct 30, 2017 | Oct 10, 2011 |
| Oracle Solaris | — | Upgrade system/network/routing/quagga to version 0.99.19-0.175.0.4.0.2.0 on Solaris 11.0 | May 29, 2017 | Oct 10, 2011 |
| Oracle_linux | — | Upgrade quagga-contribUpgrade quagga-develUpgrade quagga | Mar 28, 2017 | Oct 10, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 26, 2011 |
| Suse | — | Upgrade quagga-develUpgrade sap-aio-releaseUpgrade quagga | Feb 17, 2015 | Oct 10, 2011 |
| Ubuntu | — | Upgrade quagga | Nov 8, 2024 | Oct 10, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub