Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2236

Опубликовано: 02 июл. 2013
Источник: redhat
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

A stack-based buffer overflow flaw was found in the way the Quagga OSPFD daemon handled LSA (link-state advertisement) packets. A remote attacker could use this flaw to crash the ospfd daemon resulting in denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5quaggaWill not fix
Red Hat Enterprise Linux 7quaggaNot affected
Red Hat Enterprise Linux 6quaggaFixedRHSA-2017:079421.03.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=981124Quagga: OSPFD Potential remote code exec (stack based buffer overflow)

EPSS

Процентиль: 76%
0.00962
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

nvd
около 12 лет назад

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

debian
около 12 лет назад

Stack-based buffer overflow in the new_msg_lsa_change_notify function ...

github
больше 3 лет назад

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

oracle-oval
больше 8 лет назад

ELSA-2017-0794: quagga security and bug fix update (MODERATE)

EPSS

Процентиль: 76%
0.00962
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2