← Back

CVE-2012-0255

nvd nist
Published: Apr 5, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).

Affected (40)

Products: Quagga: Quagga
1 product
Quagga
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Quagga
Up to 0.99.20
Version 0.95
Version 0.96.1
Version 0.96.2
Version 0.96.3
Version 0.96.4
Version 0.96.5
Version 0.96
Version 0.97.0
Version 0.97.1
Version 0.97.2
Version 0.97.3
Version 0.97.4
Version 0.97.5
Version 0.98.0
Version 0.98.1
Version 0.98.2
Version 0.98.3
Version 0.98.4
Version 0.98.5
Version 0.98.6
Version 0.99.10
Version 0.99.11
Version 0.99.12
Version 0.99.13
Version 0.99.14
Version 0.99.15
Version 0.99.16
Version 0.99.17
Version 0.99.18
Version 0.99.19
Version 0.99.1
Version 0.99.2
Version 0.99.3
Version 0.99.4
Version 0.99.5
Version 0.99.6
Version 0.99.7
Version 0.99.8
Version 0.99.9

Timeline

No history available yet.