CVE-2018-5380

CWE-125Out-of-bounds Read9 documents7 sources
Severity
4.3MEDIUM
EPSS
0.9%
top 24.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5quagga/bgpdbpgd1.2.3
Ubuntuquagga< 0.99.22.4-3ubuntu1.5+1
NVDquagga/quagga1.2.2

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

4
GHSA
GHSA-265f-c4jh-jcfq: The Quagga BGP daemon (bgpd) prior to version 12022-05-13
CVEList
CVE-2018-5380: The Quagga BGP daemon (bgpd) prior to version 12018-02-19
OSV
quagga vulnerabilities2018-02-16
OSV
CVE-2018-5380: The Quagga BGP daemon (bgpd) prior to version 12018-02-13

📋Vendor Advisories

2
Ubuntu
Quagga vulnerabilities2018-02-16
Red Hat
quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash2018-02-15

💬Community

2
Bugzilla
CVE-2018-5380 quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash [fedora-all]2018-02-16
Bugzilla
CVE-2018-5380 quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash2018-02-07
CVE-2018-5380 (MEDIUM CVSS 4.3) | The Quagga BGP daemon (bgpd) prior | cvebase.io