Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-529c-38p9-5c53

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

EPSS

Процентиль: 93%
0.09623
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

CVSS3: 5.9
redhat
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

CVSS3: 7.1
nvd
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

CVSS3: 7.1
debian
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly ...

suse-cvrf
почти 8 лет назад

Security update for quagga

EPSS

Процентиль: 93%
0.09623
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-119