SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-1995

bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit)…

MEDIUM 6.3EPSS 1.74%

Does this matter?

Lower severity and a low EPSS score (1.74%). Track it; it rarely justifies an emergency change on its own.

Description

bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.

CVSS 2.0
6.3 MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
EPSS
1.74% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
quagga/quagga
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.