CVE-2018-5380
19.02.2018, 13:29
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| quagga | quagga | 𝑥 ≤ 1.2.2 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| siemens | ruggedcom_rox_ii_firmware | 𝑥 < 2.13.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libfpm_pb0 |
| ||||||||||||
| libospf0 |
| ||||||||||||
| libospfapiclient0 |
| ||||||||||||
| libquagga_pb0 |
| ||||||||||||
| libzebra1 |
| ||||||||||||
| quagga |
|
Common Weakness Enumeration
References