PT-2018-2779 · Quagga+5 · Quagga+5

CVE-2018-5379

·

Published

2018-02-13

·

Updated

2024-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quagga versions prior to 1.2.3
Description The issue is related to the implementation of the BGP protocol in Quagga software, specifically a double-free memory error when handling certain forms of UPDATE messages that contain cluster-list and/or unknown attributes. This could allow a remote attacker to cause a denial of service or potentially execute arbitrary code.
Recommendations For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the BGP daemon to minimize the risk of exploitation.

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1376
BDU:2019-01781
CESA-2018_0377
CVE-2018-5379
DLA-1286-1
DSA-4115-1
MGASA-2018-0133
OPENSUSE-SU-2018_0473-1
OPENSUSE-SU-2024:11290-1
RHSA-2018:0377
RHSA-2018_0377
SUSE-SU-2018:0455-1
SUSE-SU-2018:0456-1
SUSE-SU-2018:0457-1
SUSE-SU-2024:3426-1
USN-3573-1

Affected Products

Alt Linux
Centos
Quagga
Red Hat
Suse
Ubuntu