The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-quagga | Nov 24, 2017 | Oct 29, 2017 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Oct 29, 2017 | |
| Debian | debian-upgrade-quagga | Nov 1, 2017 | Oct 29, 2017 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-quagga | Dec 4, 2017 | Oct 29, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-quagga | Dec 4, 2017 | Oct 29, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-system-network-routing-quagga-0-99-19-0-175-3-31-0-3-0 | Apr 18, 2018 | Oct 29, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 2, 2017 | |
| Suse | — | suse-upgrade-libfpm_pb0suse-upgrade-libospf0suse-upgrade-libospfapiclient0suse-upgrade-libquagga_pb0suse-upgrade-libzebra1suse-upgrade-quaggasuse-upgrade-quagga-devel | Feb 17, 2018 | Oct 29, 2017 |
| Ubuntu | ubuntu-upgrade-quaggaubuntu-upgrade-quagga-bgpd | Oct 31, 2017 | Oct 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub