CVE-2018-5381

CWE-228CWE-8358 documents7 sources
Severity
7.5HIGH
EPSS
5.6%
top 9.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5quagga/bgpdbpgd1.2.3
Ubuntuquagga< 0.99.22.4-3ubuntu1.5+1
NVDquagga/quagga1.2.2

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

3
GHSA
GHSA-g4qp-j7fc-2xcf: The Quagga BGP daemon (bgpd) prior to version 12022-05-13
CVEList
CVE-2018-5381: The Quagga BGP daemon (bgpd) prior to version 12018-02-19
OSV
CVE-2018-5381: The Quagga BGP daemon (bgpd) prior to version 12018-02-13

📋Vendor Advisories

2
Ubuntu
Quagga vulnerabilities2018-02-16
Red Hat
quagga: Infinite loop issue triggered by invalid OPEN message allows denial-of-service2018-02-15

💬Community

2
Bugzilla
CVE-2018-5381 quagga: Infinite loop issue triggered by invalid OPEN message allows denial-of-service [fedora-all]2018-02-16
Bugzilla
CVE-2018-5381 quagga: Infinite loop issue triggered by invalid OPEN message allows denial-of-service2018-02-07
CVE-2018-5381 (HIGH CVSS 7.5) | The Quagga BGP daemon (bgpd) prior | cvebase.io