CVE-2012-0250

EUVD-2012-0286
Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
ADJACENT_NETWORK
LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
quaggaquagga
𝑥
≤ 0.99.20
quaggaquagga
0.99.1
quaggaquagga
0.99.2
quaggaquagga
0.99.3
quaggaquagga
0.99.4
quaggaquagga
0.99.5
quaggaquagga
0.99.6
quaggaquagga
0.99.7
quaggaquagga
0.99.8
quaggaquagga
0.99.9
quaggaquagga
0.99.10
quaggaquagga
0.99.11
quaggaquagga
0.99.12
quaggaquagga
0.99.13
quaggaquagga
0.99.14
quaggaquagga
0.99.15
quaggaquagga
0.99.16
quaggaquagga
0.99.17
quaggaquagga
0.99.18
quaggaquagga
0.99.19
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quagga
hardy
ignored
lucid
Fixed 0.99.20.1-0ubuntu0.10.04.2
released
maverick
ignored
natty
Fixed 0.99.20.1-0ubuntu0.11.04.2
released
oneiric
Fixed 0.99.20.1-0ubuntu0.11.10.2
released
precise
Fixed 0.99.20.1-0ubuntu0.12.04.2
released