CVE-2017-16227

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
quaggaquagga
𝑥
≤ 1.2.1
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quagga
artful
Fixed 1.1.1-3ubuntu0.1
released
trusty
Fixed 0.99.22.4-3ubuntu1.4
released
xenial
Fixed 0.99.24.1-2ubuntu1.3
released
zesty
Fixed 1.1.1-1ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libfpm_pb0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
libospf0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP4
1.1.1-17.7.1
fixed
suse enterprise server 12 SP5
1.1.1-17.7.1
fixed
libospfapiclient0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP4
1.1.1-17.7.1
fixed
suse enterprise server 12 SP5
1.1.1-17.7.1
fixed
libquagga_pb0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP4
1.1.1-17.7.1
fixed
suse enterprise server 12 SP5
1.1.1-17.7.1
fixed
libzebra1
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP4
1.1.1-17.7.1
fixed
suse enterprise server 12 SP5
1.1.1-17.7.1
fixed
quagga
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.7.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.7.1
fixed
suse enterprise server 12 SP4
1.1.1-17.7.1
fixed
suse enterprise server 12 SP5
1.1.1-17.7.1
fixed