Back

CRITICAL

quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code

Published Feb 19, 2018

Description

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

Affected products

Remediation

Red Hat statement

Glibc's heap protection mitigations render this issue more difficult to exploit, though bypasses may still be possible.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Feb 19, 2018
Updated Sep 17, 2024
Reserved Jan 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 15, 2018