Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16227

Опубликовано: 02 окт. 2017
Источник: redhat
CVSS3: 3.7

Описание

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.

A denial of service flaw was found in the way the bgpd daemon in Quagga handled the processing of large BGP update messages. A remote, previously trusted attacker could potentially use this flaw to cause bgpd to terminate existing BGP sessions, thereby leading to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5quaggaNot affected
Red Hat Enterprise Linux 6quaggaWill not fix
Red Hat Enterprise Linux 7quaggaWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1509291quagga: Incorrect AS_PATH size calculation for long paths

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.

CVSS3: 7.5
nvd
больше 8 лет назад

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.

CVSS3: 7.5
debian
больше 8 лет назад

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 al ...

CVSS3: 7.5
github
больше 3 лет назад

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость функции aspath_put пакета программ Quagga операционной системы Debian GNU/Linux, позволяющая нарушителю вызвать отказ в обслуживании

3.7 Low

CVSS3