CVE-2018-5379
published 2018-02-19CVE-2018-5379: The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or…
PriorityP262critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
39.05%
98.4th percentile
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| quagga | bgpd | >= bpgd < 1.2.3 | 1.2.3 |
| quagga | quagga | <= 1.2.2 | — |
| quagga | quagga | >= 0 < 0.99.22.4-3ubuntu1.5 | 0.99.22.4-3ubuntu1.5 |
| quagga | quagga | >= 0 < 0.99.24.1-2ubuntu1.4 | 0.99.24.1-2ubuntu1.4 |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| siemens | ruggedcom_rox_ii_firmware | < 2.13.0 | 2.13.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector: BGP UPDATE message containing cluster-list and/or unknown attributes causes double-free in bgpd; monitor for malformed BGP UPDATE messages with these attribute types on TCP port 179 ↗
- →The exploit can propagate across eBGP peers without direct attacker access — a single malicious UPDATE with optional/transitive attributes can trigger the double-free in many bgpd instances across a network; alert on unexpected bgpd crashes or restarts ↗
- →Attacker does not need to be a configured BGP peer — spoofing a malicious BGP UPDATE message within the network is sufficient; monitor for BGP sessions from unexpected sources ↗
- →Upstream security advisory with technical details available at https://www.quagga.net/security/Quagga-2018-1114.txt — use for signature/rule development ↗
- ·Glibc heap protection mitigations make exploitation harder but bypasses may still be possible; do not rely solely on OS-level mitigations ↗
- ·All versions of Quagga bgpd prior to 1.2.3 are likely affected; Siemens RUGGEDCOM ROX II all versions prior to v2.13.0 are also affected ↗
- ·No known public exploits specifically target these vulnerabilities as of the advisory date ↗
- ·Red Hat Enterprise Linux 5 and 6 quagga packages will not be fixed; RHEL 8 is not affected; RHEL 7 was addressed via RHSA-2018:0377 ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat7.5HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX II
cisa_ics·2019-04-09·CVSS 7.5
[HIGH] Siemens RUGGEDCOM ROX II
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM ROX II
Last RevisedApril 09, 2019
Alert CodeICSA-19-099-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX II
- Vulnerabilities: Double Free, Out-of-bounds Read, Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in remote code execution and/or a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following RUGGEDCOM product is affected:
- RUGGEDCOM ROX II: All
Ubuntu
Quagga vulnerabilities
vendor_ubuntu·2018-02-16·CVSS 7.1
CVE-2018-5378 [HIGH] Quagga vulnerabilities
Title: Quagga vulnerabilities
Summary: Several security issues were fixed in Quagga.
It was discovered that a double-free vulnerability existed in the
Quagga BGP daemon when processing certain forms of UPDATE message.
A remote attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2018-5379)
It was discovered that the Quagga BGP daemon did not properly bounds
check the data sent with a NOTIFY to a peer. An attacker could use this
to expose sensitive information or possibly cause a denial of service.
This issue only affected Ubuntu 17.10. (CVE-2018-5378)
It was discovered that a table overrun vulnerability existed in the
Quagga BGP daemon. An attacker in control of a configured peer could
use this to possibly expose sensitive information or possibl
Red Hat
quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
vendor_redhat·2018-02-15·CVSS 7.5
CVE-2018-5379 [HIGH] CWE-416 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
A double-free vulnerability was found in Quagga. A BGP peer could send a specially crafted UPDATE message which would cause allocated blocks of memory to be free()d more than once, potentially leading to a crash or other issues.
Statement: Glibc's heap protection mitigations render this issue more difficult to exploit, though bypasses may still be possible.
Pac
GHSA
GHSA-5prq-47x2-38gv: The Quagga BGP daemon (bgpd) prior to version 1
ghsa_unreviewed·2022-05-13
CVE-2018-5379 [CRITICAL] CWE-415 GHSA-5prq-47x2-38gv: The Quagga BGP daemon (bgpd) prior to version 1
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
OSV
quagga vulnerabilities
osv·2018-02-16·CVSS 5.9
CVE-2018-5379 [MEDIUM] quagga vulnerabilities
quagga vulnerabilities
It was discovered that a double-free vulnerability existed in the
Quagga BGP daemon when processing certain forms of UPDATE message.
A remote attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2018-5379)
It was discovered that the Quagga BGP daemon did not properly bounds
check the data sent with a NOTIFY to a peer. An attacker could use this
to expose sensitive information or possibly cause a denial of service.
This issue only affected Ubuntu 17.10. (CVE-2018-5378)
It was discovered that a table overrun vulnerability existed in the
Quagga BGP daemon. An attacker in control of a configured peer could
use this to possibly expose sensitive information or possibly cause
a denial of service. (CVE-2018-5380)
It was discovered
OSV
CVE-2018-5379: The Quagga BGP daemon (bgpd) prior to version 1
osv·2018-02-13·CVSS 9.8
CVE-2018-5379 [CRITICAL] CVE-2018-5379: The Quagga BGP daemon (bgpd) prior to version 1
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
No detection rules found.
No public exploits indexed.
Tenable
Critical Vulnerability in Siemens Spectrum Power (CVE-2019-6579) Patched in Monthly Advisory
blogs_tenable·2019-04-10·CVSS 9.8
[CRITICAL] Critical Vulnerability in Siemens Spectrum Power (CVE-2019-6579) Patched in Monthly Advisory
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code [fedora-all]
bugzilla·2018-02-16·CVSS 7.5
CVE-2018-5379 [HIGH] CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code [fedora-all]
CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
bugzilla·2018-02-07·CVSS 7.5
CVE-2018-5379 [HIGH] CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code
The Quagga BGP daemon, bgpd, can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes.
This issue can be triggered by an optional/transitive UPDATE attribute, that all conforming eBGP speakers should pass along. This means this may triggerable in many affected Quagga bgpd processes across a wide area of a network, because of just one UPDATE message.
This issue could result in a crash of bgpd, or even allow a remote attacker to gain control of an affected bgpd process.
All versions are likely affected.
Discussion:
Acknowledgments:
Name: the Quagga project
---
C
http://savannah.nongnu.org/forum/forum.php?forum_id=9095http://www.kb.cert.org/vuls/id/940439http://www.securityfocus.com/bid/103105https://access.redhat.com/errata/RHSA-2018:0377https://cert-portal.siemens.com/productcert/pdf/ssa-451142.pdfhttps://gogs.quagga.net/Quagga/quagga/src/master/doc/security/Quagga-2018-1114.txthttps://lists.debian.org/debian-lts-announce/2018/02/msg00021.htmlhttps://security.gentoo.org/glsa/201804-17https://usn.ubuntu.com/3573-1/https://www.debian.org/security/2018/dsa-4115http://savannah.nongnu.org/forum/forum.php?forum_id=9095http://www.kb.cert.org/vuls/id/940439http://www.securityfocus.com/bid/103105https://access.redhat.com/errata/RHSA-2018:0377https://cert-portal.siemens.com/productcert/pdf/ssa-451142.pdfhttps://gogs.quagga.net/Quagga/quagga/src/master/doc/security/Quagga-2018-1114.txthttps://lists.debian.org/debian-lts-announce/2018/02/msg00021.htmlhttps://security.gentoo.org/glsa/201804-17https://usn.ubuntu.com/3573-1/https://www.debian.org/security/2018/dsa-4115
2018-02-19
Published