Search CVE reports


Toggle filters

31 – 40 of 71 results


CVE-2023-41360

Low priority
Fixed

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Ignored
quagga Not in release Not in release Fixed Fixed
Show less packages

CVE-2023-41359

Medium priority
Not affected

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Ignored
quagga Not in release Not affected Not affected
Show less packages

CVE-2023-41358

Medium priority
Fixed

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Ignored
quagga Not in release Not in release Fixed Fixed
Show less packages

CVE-2023-38802

Medium priority
Fixed

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Not in release
quagga Not in release Not in release Not affected Not affected
Show less packages

CVE-2022-37032

Medium priority

Some fixes available 11 of 13

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Fixed Not in release
quagga Not in release Not in release Not in release Fixed Vulnerable
Show less packages

CVE-2021-44038

Low priority
Vulnerable

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package...

1 affected package

quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2012-5521

Low priority
Vulnerable

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

1 affected package

quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2017-3224

Low priority
Vulnerable

Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA,...

1 affected package

quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2018-5381

Medium priority
Fixed

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid...

1 affected package

quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quagga
Show less packages

CVE-2018-5380

Low priority
Fixed

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

1 affected package

quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quagga
Show less packages