CVE-2018-5381
Summary
| CVE | CVE-2018-5381 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-19 13:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CERT Vulnerability Notes Database |
CERT-VN |
www.kb.cert.org |
Third Party Advisory, US Government Resource |
| cert-portal.siemens.com/productcert/pdf/ssa-451142.pdf |
CONFIRM |
cert-portal.siemens.com |
Mitigation, Third Party Advisory |
| Debian -- Security Information -- DSA-4115-1 quagga |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 1286-1] quagga security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Quagga Routing Software - News: Quagga 1.2.3 Release, with significant BGP security fixes [Savannah] |
CONFIRM |
savannah.nongnu.org |
Third Party Advisory |
| Quagga: Multiple vulnerabilities (GLSA 201804-17) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| USN-3573-1: Quagga vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Quagga/quagga: Primary Quagga git repository - Quagga |
CONFIRM |
gogs.quagga.net |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690650 Free Berkeley Software Distribution (FreeBSD) Security Update for quagga (e15a22ce-f16f-446b-9ca7-6859350c2e75)
- 710242 Gentoo Linux Quagga Multiple Vulnerabilities (GLSA 201804-17)