CVE-2016-1245
22.02.2017, 23:59
It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| quagga | quagga | 𝑥 ≤ 1.0.20160315 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libfpm_pb0 |
| ||||||||||||||
| libospf0 |
| ||||||||||||||
| libospfapiclient0 |
| ||||||||||||||
| libquagga_pb0 |
| ||||||||||||||
| libzebra1 |
| ||||||||||||||
| quagga |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References