CVE-2007-4826: Null Pointer Dereference
Published Sep 12, 2007
·Updated
bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is enabled.
Affected Software
28 affected components
Quagga Quagga=0.99.2
Quagga Quagga=0.97.5
Quagga Quagga=0.95
Quagga Quagga=0.98.3
Quagga Quagga=0.96.3
Quagga Quagga=0.99.4
Quagga Quagga=0.99.7
Quagga Quagga=0.99.5
Quagga Quagga=0.96.5
Quagga Quagga=0.98.0
Quagga Quagga=0.96.1
Quagga Quagga=0.98.1
Quagga Quagga=0.96.4
Quagga Quagga=0.98.5
Quagga Quagga=0.97.3
Quagga Quagga=0.99.3
Quagga Quagga<=0.99.8
Quagga Quagga=0.99.6
Quagga Quagga=0.98.6
Quagga Quagga=0.97.4
Quagga Quagga=0.98.4
Quagga Quagga=0.98.2
Quagga Quagga=0.97.1
Quagga Quagga=0.97.0
Quagga Quagga=0.96.2
Quagga Quagga=0.99.1
Quagga Quagga=0.97.2
Quagga Quagga=0.96
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 12, 2007
CVE Published
10:17 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4826?
CVE-2007-4826 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2007-4826?
To fix CVE-2007-4826, update Quagga to version 0.99.9 or later.
3
What versions of Quagga are affected by CVE-2007-4826?
CVE-2007-4826 affects Quagga versions 0.95 through 0.99.8.
4
What type of attacks can exploit CVE-2007-4826?
CVE-2007-4826 can be exploited by sending a malformed OPEN message or COMMUNITY attribute to a BGP peer.
5
Is debugging mode necessary for CVE-2007-4826 to be exploited?
Debugging mode is not necessary for the initial attack vector but is required for exploiting the COMMUNITY attribute.