CVE-2013-6051

6 documents5 sources
Severity
4.3MEDIUM
EPSS
0.4%
top 37.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14
Latest updateMay 17

Description

The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDquagga/quagga0.99.21

🔴Vulnerability Details

2
GHSA
GHSA-v7c4-xhg8-w2fh: The bgp_attr_unknown function in bgp_attr2022-05-17
CVEList
CVE-2013-6051: The bgp_attr_unknown function in bgp_attr2013-12-14

📋Vendor Advisories

1
Red Hat
quagga: bgp crash when receiving bgp updates2013-11-25

💬Community

2
Bugzilla
CVE-2013-6051 quagga: bgp crash when receiving bgp updates2013-12-16
Bugzilla
CVE-2013-6051 quagga: bgp crash when receiving bgp updates [fedora-18]2013-12-16