CVE-2018-5379

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
quaggaquagga
𝑥
≤ 1.2.2
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
17.10
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_server_tus
7.4
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_workstation
7.0
siemensruggedcom_rox_ii_firmware
𝑥
< 2.13.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quagga
artful
Fixed 1.1.1-3ubuntu0.2
released
trusty
Fixed 0.99.22.4-3ubuntu1.5
released
xenial
Fixed 0.99.24.1-2ubuntu1.4
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libfpm_pb0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
libospf0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
libospfapiclient0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
libquagga_pb0
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
libzebra1
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
quagga
suse enterprise sap 12 SP2
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP3
1.1.1-17.7.1
fixed
suse enterprise sap 12 SP5
1.1.1-17.13.1
fixed
suse enterprise server 12 SP2
1.1.1-17.7.1
fixed
suse enterprise server 12 SP3
1.1.1-17.13.1
fixed
suse enterprise server 12 SP5
1.1.1-17.13.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
quagga
RHEL 7
0:0.99.22.4-5.el7_4
fixed
quagga-contrib
RHEL 7
0:0.99.22.4-5.el7_4
fixed
quagga-devel
RHEL 7
0:0.99.22.4-5.el7_4
fixed