Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
BID:60955
Info
Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 60955 |
| Class: | Unknown |
| CVE: |
CVE-2013-2236 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2013 12:00AM |
| Updated: | Mar 23 2017 01:01AM |
| Credit: | Ricky Charlet |
| Vulnerable: |
Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Quagga Quagga 0.99.22 Oracle Solaris 11 Oracle Solaris 10 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Oracle Solaris 11.1.17.5.0 |
Discussion
Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
Quagga is prone to a stack-based buffer-overflow vulnerability because it fails to properly validate user-supplied input before copying it into a fixed-length buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
Quagga 0.99.22 is vulnerable; other versions may also be affected.
Quagga is prone to a stack-based buffer-overflow vulnerability because it fails to properly validate user-supplied input before copying it into a fixed-length buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
Quagga 0.99.22 is vulnerable; other versions may also be affected.
Exploit / POC
Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
-
Mandriva lib64quagga-devel-0.99.20.1-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64quagga0-0.99.20.1-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva quagga-0.99.20.1-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva quagga-contrib-0.99.20.1-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
References:
References: