Back

LOW

quagga bgpd DoS

Published Sep 12, 2007

Description

bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is enabled.

Affected products

Remediation

Red Hat statement

Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=285691 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.

Metrics

Weaknesses (0)

No CWE recorded.

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 12, 2007
Updated Aug 7, 2024
Reserved Sep 11, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 7, 2007