Tuesday, September 14, 2010

quagga: buffer overflow

Users of quagga please be advised of a buffer overflow vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:174: [MDVSA-2010:174] quagga buffer overflow
Problem Description:



Stack-based buffer overflow in the bgp_route_refresh_receive

function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows

remote authenticated users to cause a denial of service (daemon

crash) or possibly execute arbitrary code via a malformed Outbound

Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message

(CVE-2010-2948).



bgpd in Quagga before 0.99.17 does not properly parse AS paths, which

allows remote attackers to cause a denial of service (NULL pointer

dereference and daemon crash) via an unknown AS type in an AS path

attribute in a BGP UPDATE message (CVE-2010-2949).


Read more at www.criticalwatch.com
 

No comments:

Post a Comment