CVE-2018-12066Uncontrolled Resource Consumption in Project Bird

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 89.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 14

Description

BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDbird_project/bird< 1.6.4
Debianbird_project/bird< 1.6.4-1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6f55-8mp8-93rv: BIRD Internet Routing Daemon before 12022-05-14
CVEList
CVE-2018-12066: BIRD Internet Routing Daemon before 12018-06-08
OSV
CVE-2018-12066: BIRD Internet Routing Daemon before 12018-06-08

📋Vendor Advisories

1
Debian
CVE-2018-12066: bird - BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial o...2018

💬Community

3
Bugzilla
CVE-2018-12066 bird: Stack overflow in BGP mask expressions [epel-all]2018-06-07
Bugzilla
CVE-2018-12066 bird: Stack overflow in BGP mask expressions [fedora-all]2018-06-07
Bugzilla
CVE-2018-12066 bird: Stack overflow in BGP mask expressions2018-06-07
CVE-2018-12066 — Uncontrolled Resource Consumption | cvebase