Quagga CVE-2018-5379 Remote Code Execution Vulnerability
BID:103105
CVE-2018-5379 |Info
Quagga CVE-2018-5379 Remote Code Execution Vulnerability
| Bugtraq ID: | 103105 |
| Class: | Unknown |
| CVE: |
CVE-2018-5379 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2018 12:00AM |
| Updated: | Apr 10 2019 11:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Siemens RUGGEDCOM ROX II 2.9 Siemens RUGGEDCOM ROX II 2.12 Siemens RUGGEDCOM ROX II 2.11 Siemens RUGGEDCOM ROX II 2.10 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Quagga Quagga 1.2.2 Quagga Quagga 1.2.1 Quagga Quagga 1.2 Quagga Quagga 1.1.1 Quagga Quagga 1.1 Quagga Quagga 1.0.20160309 Quagga Quagga 0.99.24 Quagga Quagga 0.99.22 Quagga Quagga 0.99.21 Quagga Quagga 0.99.17 Quagga Quagga 0.99.16 Quagga Quagga 0.99.15 Quagga Quagga 0.99.14 Quagga Quagga 0.99.13 Quagga Quagga 0.99.12 Quagga Quagga 0.99.11 Quagga Quagga 0.99.10 Quagga Quagga 0.99.9 Quagga Quagga 0.99.8 Quagga Quagga 0.99.7 Quagga Quagga 0.99.6 Quagga Quagga 0.99.5 Quagga Quagga 0.99.4 Quagga Quagga 0.99.3 Quagga Quagga 0.99.2 Quagga Quagga 0.99.1 Quagga Quagga 0.98.6 Quagga Quagga 0.98.5 Quagga Quagga 0.98.3 Quagga Quagga 0.98.2 Quagga Quagga 0.98.1 Quagga Quagga 0.98 Quagga Quagga 0.97.5 Quagga Quagga 0.97.3 Quagga Quagga 0.97.2 Quagga Quagga 0.97.1 Quagga Quagga 0.97 Quagga Quagga 0.96.5 Quagga Quagga 0.96.3 Quagga Quagga 0.96.2 Quagga Quagga 1.0.20161017 Quagga Quagga 1.0 Quagga Quagga 0.99.24.1 Quagga Quagga 0.99.22.3 Quagga Quagga 0.99.22.2 Quagga Quagga 0.99.22.1 Quagga Quagga 0.99.20.1 Quagga Quagga 0.99.20 Quagga Quagga 0.99.19 Quagga Quagga 0.99.18 Quagga Quagga 0.98.4 Quagga Quagga 0.97.4 Quagga Quagga 0.96.4 Quagga Quagga 0.96.1 Quagga Quagga 0.96 Quagga Quagga 0.95 Quagga Quagga 0.93 Oracle Solaris 11.3 |
| Not Vulnerable: |
Siemens RUGGEDCOM ROX II 2.13 Quagga Quagga 1.2.3 |
Discussion
Quagga CVE-2018-5379 Remote Code Execution Vulnerability
Quagga is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause a denial-of-service condition.
Versions prior to Quagga 1.2.3 are vulnerable.
Quagga is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause a denial-of-service condition.
Versions prior to Quagga 1.2.3 are vulnerable.
Exploit / POC
Quagga CVE-2018-5379 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Quagga CVE-2018-5379 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Quagga CVE-2018-5379 Remote Code Execution Vulnerability
References:
References:
- Bug 1542985 - (CVE-2018-5379) CVE-2018-5379 quagga: Double free vulnerability in (Red Hat Bugzilla)
- CVE-2018-5379 (Red Hat Bugzilla)
- Advisory (ICSA-19-099-05) Siemens RUGGEDCOM ROX II (ICS-CERT)
- Oracle Solaris Third Party Bulletin - April 2018 (Oracle)
- Quagga Security Note 2018-1114 (Quagga)