CVE-2012-0249

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 UNKNOWN
ADJACENT_NETWORK
LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
quaggaquagga
𝑥
≤ 0.99.20
quaggaquagga
0.95
quaggaquagga
0.96
quaggaquagga
0.96.1
quaggaquagga
0.96.2
quaggaquagga
0.96.3
quaggaquagga
0.96.4
quaggaquagga
0.96.5
quaggaquagga
0.97.0
quaggaquagga
0.97.1
quaggaquagga
0.97.2
quaggaquagga
0.97.3
quaggaquagga
0.97.4
quaggaquagga
0.97.5
quaggaquagga
0.98.0
quaggaquagga
0.98.1
quaggaquagga
0.98.2
quaggaquagga
0.98.3
quaggaquagga
0.98.4
quaggaquagga
0.98.5
quaggaquagga
0.98.6
quaggaquagga
0.99.1
quaggaquagga
0.99.2
quaggaquagga
0.99.3
quaggaquagga
0.99.4
quaggaquagga
0.99.5
quaggaquagga
0.99.6
quaggaquagga
0.99.7
quaggaquagga
0.99.8
quaggaquagga
0.99.9
quaggaquagga
0.99.10
quaggaquagga
0.99.11
quaggaquagga
0.99.12
quaggaquagga
0.99.13
quaggaquagga
0.99.14
quaggaquagga
0.99.15
quaggaquagga
0.99.16
quaggaquagga
0.99.17
quaggaquagga
0.99.18
quaggaquagga
0.99.19
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quagga
precise
Fixed 0.99.20.1-0ubuntu0.12.04.2
released
oneiric
Fixed 0.99.20.1-0ubuntu0.11.10.2
released
natty
Fixed 0.99.20.1-0ubuntu0.11.04.2
released
maverick
ignored
lucid
Fixed 0.99.20.1-0ubuntu0.10.04.2
released
hardy
ignored