Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5379

Опубликовано: 15 фев. 2018
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

A double-free vulnerability was found in Quagga. A BGP peer could send a specially crafted UPDATE message which would cause allocated blocks of memory to be free()d more than once, potentially leading to a crash or other issues.

Отчет

Glibc's heap protection mitigations render this issue more difficult to exploit, though bypasses may still be possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5quaggaWill not fix
Red Hat Enterprise Linux 6quaggaWill not fix
Red Hat Enterprise Linux 8quaggaNot affected
Red Hat Enterprise Linux 7quaggaFixedRHSA-2018:037728.02.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1542985quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code

EPSS

Процентиль: 95%
0.20073
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

CVSS3: 7.5
nvd
больше 7 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

CVSS3: 7.5
debian
больше 7 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free me ...

CVSS3: 9.8
github
больше 3 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

oracle-oval
больше 7 лет назад

ELSA-2018-0377: quagga security update (IMPORTANT)

EPSS

Процентиль: 95%
0.20073
Средний

8.1 High

CVSS3

Уязвимость CVE-2018-5379