Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5380

Опубликовано: 15 фев. 2018
Источник: redhat
CVSS3: 4.3

Описание

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

A vulnerability was found in Quagga, in the log formatting code. Specially crafted messages sent by BGP peers could cause Quagga to read one element past the end of certain static arrays, causing arbitrary binary data to appear in the logs or potentially, a crash.

Отчет

Red Hat Product Security has given this vulnerability a rating of Low. We believe the potential for a crash on supported architectures is very small.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5quaggaWill not fix
Red Hat Enterprise Linux 6quaggaWill not fix
Red Hat Enterprise Linux 7quaggaWill not fix
Red Hat Enterprise Linux 8quaggaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1542990quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

CVSS3: 4.3
nvd
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

CVSS3: 4.3
debian
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun intern ...

CVSS3: 4.3
github
больше 3 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

CVSS3: 4.3
fstec
почти 8 лет назад

Уязвимость демона bgpd пакета программ Quagga, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS3