Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
BID:42635
Info
Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 42635 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2948 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2010 12:00AM |
| Updated: | May 07 2015 05:02PM |
| Credit: | Jan iankko Lieskovsky |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 SuSE openSUSE 11.3 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Quagga Quagga Routing Software Suite 0.99.16 Quagga Quagga Routing Software Suite 0.99.15 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Quagga Quagga Routing Software Suite 0.99.17 |
Discussion
Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
Quagga is prone to a stack-based buffer-overflow vulnerability.
Successful exploits will allow attackers to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Quagga 0.99.17 are vulnerable.
Quagga is prone to a stack-based buffer-overflow vulnerability.
Successful exploits will allow attackers to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Quagga 0.99.17 are vulnerable.
Exploit / POC
Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Debian Linux 5.0 ia-64
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 6.06 LTS sparc
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Debian Linux 5.0 s/390
Ubuntu Ubuntu Linux 9.10 lpia
Debian Linux 5.0 mipsel
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Ubuntu Ubuntu Linux 10.04 powerpc
Debian Linux 5.0 hppa
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Ubuntu Ubuntu Linux 9.10 i386
Ubuntu Ubuntu Linux 10.04 amd64
Debian Linux 5.0 armel
Ubuntu Ubuntu Linux 9.10 ARM
Debian Linux 5.0
MandrakeSoft Corporate Server 4.0
Ubuntu Ubuntu Linux 9.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS i386
Debian Linux 5.0 amd64
Ubuntu Ubuntu Linux 10.04 ARM
Debian Linux 5.0 mips
Debian Linux 5.0 powerpc
Ubuntu Ubuntu Linux 10.04 sparc
Debian Linux 5.0 sparc
Ubuntu Ubuntu Linux 10.04 i386
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.13-1ubuntu0.1_s parc.deb
Debian Linux 5.0 ia-64
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_ia64.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_ia64.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu quagga-doc_0.99.9-2ubuntu1.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.9 -2ubuntu1.4_all.deb -
Ubuntu quagga_0.99.9-2ubuntu1.4_powerpc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.9-2ubuntu1.4_po werpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu quagga-doc_0.99.9-2ubuntu1.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.9 -2ubuntu1.4_all.deb -
Ubuntu quagga_0.99.9-2ubuntu1.4_sparc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.9-2ubuntu1.4_sp arc.deb
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.13-1ubuntu0.1_p owerpc.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu quagga-doc_0.99.2-1ubuntu3.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.2 -1ubuntu3.7_all.deb -
Ubuntu quagga_0.99.2-1ubuntu3.7_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.2-1ub untu3.7_sparc.deb
Debian Linux 5.0 alpha
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_alpha.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_alpha.deb
Debian Linux 5.0 ia-32
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_i386.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_i386.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu quagga-doc_0.99.9-2ubuntu1.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.9 -2ubuntu1.4_all.deb -
Ubuntu quagga_0.99.9-2ubuntu1.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.9-2ub untu1.4_amd64.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu quagga-doc_0.99.2-1ubuntu3.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.2 -1ubuntu3.7_all.deb -
Ubuntu quagga_0.99.2-1ubuntu3.7_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.2-1ub untu3.7_powerpc.deb
Debian Linux 5.0 s/390
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_s390.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_s390.deb
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.13-1ubuntu0.1_l pia.deb
Debian Linux 5.0 mipsel
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_mipsel.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_mipsel.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu quagga-doc_0.99.9-2ubuntu1.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.9 -2ubuntu1.4_all.deb -
Ubuntu quagga_0.99.9-2ubuntu1.4_lpia.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.9-2ubuntu1.4_lp ia.deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu quagga-doc_0.99.2-1ubuntu3.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.2 -1ubuntu3.7_all.deb -
Ubuntu quagga_0.99.2-1ubuntu3.7_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.2-1ub untu3.7_i386.deb
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu quagga-doc_0.99.2-1ubuntu3.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.2 -1ubuntu3.7_all.deb -
Ubuntu quagga_0.99.2-1ubuntu3.7_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.2-1ub untu3.7_amd64.deb
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu quagga-doc_0.99.15-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 5-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.15-1ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.15-1ubuntu0.1_p owerpc.deb
Debian Linux 5.0 hppa
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_hppa.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_hppa.deb
Debian Linux 5.0 m68k
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb
Debian Linux 5.0 arm
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_arm.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_arm.deb
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.13-1u buntu0.1_i386.deb
Ubuntu Ubuntu Linux 10.04 amd64
-
Ubuntu quagga-doc_0.99.15-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 5-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.15-1ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.15-1u buntu0.1_amd64.deb
Debian Linux 5.0 armel
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_armel.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_armel.deb
Ubuntu Ubuntu Linux 9.10 ARM
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_armel.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.13-1ubuntu0.1_a rmel.deb
Debian Linux 5.0
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb
MandrakeSoft Corporate Server 4.0
-
Mandriva libquagga0-0.99.17-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libquagga0-devel-0.99.17-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva quagga-0.99.17-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva quagga-contrib-0.99.17-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu quagga-doc_0.99.13-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 3-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.13-1ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.13-1u buntu0.1_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu quagga-doc_0.99.9-2ubuntu1.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.9 -2ubuntu1.4_all.deb -
Ubuntu quagga_0.99.9-2ubuntu1.4_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.9-2ub untu1.4_i386.deb
Debian Linux 5.0 amd64
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_amd64.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_amd64.deb
Ubuntu Ubuntu Linux 10.04 ARM
-
Ubuntu quagga-doc_0.99.15-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 5-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.15-1ubuntu0.1_armel.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.15-1ubuntu0.1_a rmel.deb
Debian Linux 5.0 mips
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_mips.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_mips.deb
Debian Linux 5.0 powerpc
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_powerpc.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_powerpc.deb
Ubuntu Ubuntu Linux 10.04 sparc
-
Ubuntu quagga-doc_0.99.15-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 5-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.15-1ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/q/quagga/quagga_0.99.15-1ubuntu0.1_s parc.deb
Debian Linux 5.0 sparc
-
Debian quagga-doc_0.99.10-1lenny3_all.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.99. 10-1lenny3_all.deb -
Debian quagga_0.99.10-1lenny3_sparc.deb
http://security.debian.org/pool/updates/main/q/quagga/quagga_0.99.10-1 lenny3_sparc.deb
Ubuntu Ubuntu Linux 10.04 i386
-
Ubuntu quagga-doc_0.99.15-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga-doc_0.99.1 5-1ubuntu0.1_all.deb -
Ubuntu quagga_0.99.15-1ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/q/quagga/quagga_0.99.15-1u buntu0.1_i386.deb
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva lib64quagga0-0.99.17-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64quagga0-devel-0.99.17-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva quagga-0.99.17-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva quagga-contrib-0.99.17-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Quagga bgpd Route-Refresh Message Stack Buffer Overflow Vulnerability
References:
References:
- Bug 626783 - Quagga (bgpd): Stack buffer overflow by processing certain Route-Re (Red Hat)
- CVE Request -- Quagga (bgpd) [two ids] -- 1, Stack buffer overflow by processing (Jan iankko Lieskovsky)
- Quagga 0.99.17 Released (Quagga)
- Quagga Software Suite Homepage (Quagga)
- Rugged Operating system on LinuX (ROX) Release Notes v1.15.0 (RuggedCom)