CVE-2007-1995: Input Validation
bgpd/bgpattr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MPREACHNLRI and MPUNREACHNLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1995?
CVE-2007-1995 is classified as a denial of service vulnerability that can crash the Quagga daemon.
How do I fix CVE-2007-1995?
To fix CVE-2007-1995, update Quagga to version 0.99.7 or later, which addresses the vulnerability.
Which versions of Quagga are affected by CVE-2007-1995?
CVE-2007-1995 affects Quagga versions 0.98.6 and earlier, and 0.99.6 and earlier.
What causes CVE-2007-1995?
CVE-2007-1995 is caused by the lack of validation of length values in MP_REACH_NLRI and MP_UNREACH_NLRI attributes in crafted update messages.
Can CVE-2007-1995 be exploited remotely?
Yes, CVE-2007-1995 can be exploited remotely by attackers sending specially crafted UPDATE messages.