CVE-2010-1674

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.

References

http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html

http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00009.html

http://rhn.redhat.com/errata/RHSA-2012-1258.html

http://secunia.com/advisories/43499

http://secunia.com/advisories/43770

http://secunia.com/advisories/48106

http://security.gentoo.org/glsa/glsa-201202-02.xml

http://www.debian.org/security/2011/dsa-2197

http://www.mandriva.com/security/advisories?name=MDVSA-2011:058

http://www.osvdb.org/71259

http://www.quagga.net/news2.php?y=2011&m=3&d=21#id1300723200

http://www.securityfocus.com/bid/46942

http://www.vupen.com/english/advisories/2011/0711

https://bugzilla.redhat.com/show_bug.cgi?id=654603

https://exchange.xforce.ibmcloud.com/vulnerabilities/66211

Details

Source: MITRE

Published: 2011-03-29

Updated: 2018-01-06

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.98.6:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.1:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.2:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.4:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.5:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.6:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.7:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.8:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.9:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.10:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.12:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.13:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.14:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.15:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:0.99.16:*:*:*:*:*:*:*

cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:* versions up to 0.99.17 (inclusive)

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
80751Oracle Solaris Third-Party Patch Update : quagga (multiple_denial_of_service_vulnerabilities4)NessusSolaris Local Security Checks
medium
76006openSUSE Security Update : quagga (openSUSE-SU-2011:0274-2)NessusSuSE Local Security Checks
medium
75722openSUSE Security Update : quagga (openSUSE-SU-2011:0274-1)NessusSuSE Local Security Checks
medium
68617Oracle Linux 5 : quagga (ELSA-2012-1258)NessusOracle Linux Local Security Checks
high
68242Oracle Linux 6 : quagga (ELSA-2011-0406)NessusOracle Linux Local Security Checks
medium
62094Scientific Linux Security Update : quagga on SL5.x i386/x86_64 (20120912)NessusScientific Linux Local Security Checks
high
62069RHEL 5 : quagga (RHSA-2012:1258)NessusRed Hat Local Security Checks
high
62066CentOS 5 : quagga (CESA-2012:1258)NessusCentOS Local Security Checks
high
61005Scientific Linux Security Update : quagga on SL6.x i386/x86_64NessusScientific Linux Local Security Checks
medium
59789Quagga < 0.99.18 BGPD Multiple Denial of Service VulnerabilitiesNessusMisc.
medium
58081GLSA-201202-02 : Quagga: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
57249SuSE 10 Security Update : quagga (ZYPP Patch Number 7406)NessusSuSE Local Security Checks
medium
53796openSUSE Security Update : quagga (openSUSE-SU-2011:0274-1)NessusSuSE Local Security Checks
medium
53452Fedora 15 : quagga-0.99.18-2.fc15 (2011-3990)NessusFedora Local Security Checks
medium
53366Fedora 14 : quagga-0.99.18-1.fc14 (2011-3922)NessusFedora Local Security Checks
medium
53365Fedora 13 : quagga-0.99.18-1.fc13 (2011-3916)NessusFedora Local Security Checks
medium
53266FreeBSD : quagga -- two DoS vulnerabilities (b2a40507-5c88-11e0-9e85-00215af774f0)NessusFreeBSD Local Security Checks
medium
53255SuSE 10 Security Update : quagga (ZYPP Patch Number 7355)NessusSuSE Local Security Checks
medium
53254SuSE 11.1 Security Update : quagga (SAT Patch Number 4023)NessusSuSE Local Security Checks
medium
53250SuSE9 Security Update : quagga (YOU Patch Number 12685)NessusSuSE Local Security Checks
medium
53245RHEL 6 : quagga (RHSA-2011:0406)NessusRed Hat Local Security Checks
medium
53219Ubuntu 6.06 LTS / 8.04 LTS / 9.10 / 10.04 LTS / 10.10 : quagga vulnerabilities (USN-1095-1)NessusUbuntu Local Security Checks
medium
52741Debian DSA-2197-1 : quagga - denial of serviceNessusDebian Local Security Checks
medium