MEDIUM
security flaw
Published May 5, 2006
5.0
MEDIUMCVSS 2.0
EPSS 10.36%
Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Affected products
No data.
OR
- ≤ 0.99.3
- 0.95
- 0.96.2
- 0.96.3
- 0.98.5
No data.
Red Hat Enterprise Linux 3
quagga-0:0.96.2-11.3E
Fixed · RHSA-2006:0525
Red Hat Enterprise Linux 4
quagga-0:0.98.3-2.4E
Fixed · RHSA-2006:0525
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2006:0533
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2006:0533
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | quagga-0:0.96.2-11.3E | Fixed | RHSA-2006:0525 |
| Red Hat Enterprise Linux 4 | quagga-0:0.98.3-2.4E | Fixed | RHSA-2006:0525 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2006:0533 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2006:0533 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (28)
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc vendor-advisoryx_refsource_SGI
- http://bugzilla.quagga.net/show_bug.cgi?id=262 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/19910 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/20137 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20138 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20221 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20420 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20421 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20782 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21159 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1016204 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2006/dsa-1059 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml vendor-advisoryx_refsource_GENTOO
- http://www.novell.com/linux/security/advisories/2006_17_sr.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/25225 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0525.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2006-0533.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/432823/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/432856/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17808 vdb-entryx_refsource_BIDExploitPatch
- https://access.redhat.com/security/cve/CVE-2006-2224 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618092 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-2225 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26251 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-2224
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10775 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/284-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-2224
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 5, 2006
Updated Aug 7, 2024
Reserved May 5, 2006
Link CVE-2006-2224
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-2225 Assigner mitre
Published May 5, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-2225