Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade quagga | Aug 30, 2017 | Apr 5, 2012 |
| Centos_linux | — | Upgrade quagga-develUpgrade quaggaUpgrade quagga-contrib | Dec 1, 2016 | Apr 5, 2012 |
| Freebsd | — | Upgrade quaggaUpgrade quagga-re | Dec 10, 2025 | Mar 24, 2012 |
| Gentoo Linux | — | Upgrade net-misc/quagga. | Oct 30, 2017 | Apr 5, 2012 |
| Oracle Solaris | — | Upgrade system/network/routing/quagga to version 0.99.19-0.175.0.10.0.1.0 on Solaris 11.0 | May 29, 2017 | Apr 5, 2012 |
| Oracle_linux | — | Upgrade quagga-contribUpgrade quagga-develUpgrade quagga | Mar 28, 2017 | Apr 5, 2012 |
| Suse | — | Upgrade quaggaUpgrade quagga-devel | Dec 12, 2013 | Apr 5, 2012 |
| Ubuntu | — | Upgrade quagga | Nov 8, 2024 | Apr 5, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub