First published: Thu Nov 18 2010(Updated: )
A security flaw was found in the way Quagga bgpd daemon processed certain route metrics information. A configured BGP peer could use this flaw to send a BGP message with specially-crafted value of AS-path attribute, which would cause the bgpd daemon on all systems on the route the message travels to reset the BGP session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quagga Routing Software Suite | <=0.99.17 | |
Quagga Routing Software Suite | =0.95 | |
Quagga Routing Software Suite | =0.96 | |
Quagga Routing Software Suite | =0.96.1 | |
Quagga Routing Software Suite | =0.96.2 | |
Quagga Routing Software Suite | =0.96.3 | |
Quagga Routing Software Suite | =0.96.4 | |
Quagga Routing Software Suite | =0.96.5 | |
Quagga Routing Software Suite | =0.97.0 | |
Quagga Routing Software Suite | =0.97.1 | |
Quagga Routing Software Suite | =0.97.2 | |
Quagga Routing Software Suite | =0.97.3 | |
Quagga Routing Software Suite | =0.97.4 | |
Quagga Routing Software Suite | =0.97.5 | |
Quagga Routing Software Suite | =0.98.0 | |
Quagga Routing Software Suite | =0.98.1 | |
Quagga Routing Software Suite | =0.98.2 | |
Quagga Routing Software Suite | =0.98.3 | |
Quagga Routing Software Suite | =0.98.4 | |
Quagga Routing Software Suite | =0.98.5 | |
Quagga Routing Software Suite | =0.98.6 | |
Quagga Routing Software Suite | =0.99.1 | |
Quagga Routing Software Suite | =0.99.2 | |
Quagga Routing Software Suite | =0.99.3 | |
Quagga Routing Software Suite | =0.99.4 | |
Quagga Routing Software Suite | =0.99.5 | |
Quagga Routing Software Suite | =0.99.6 | |
Quagga Routing Software Suite | =0.99.7 | |
Quagga Routing Software Suite | =0.99.8 | |
Quagga Routing Software Suite | =0.99.9 | |
Quagga Routing Software Suite | =0.99.10 | |
Quagga Routing Software Suite | =0.99.11 | |
Quagga Routing Software Suite | =0.99.12 | |
Quagga Routing Software Suite | =0.99.13 | |
Quagga Routing Software Suite | =0.99.14 | |
Quagga Routing Software Suite | =0.99.15 | |
Quagga Routing Software Suite | =0.99.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1675 has a moderate severity level due to its potential impact on BGP routing stability.
To fix CVE-2010-1675, upgrade to Quagga version 0.99.18 or later, which resolves this vulnerability.
CVE-2010-1675 affects multiple versions of the Quagga Routing Software Suite, specifically versions up to 0.99.17 inclusive.
CVE-2010-1675 can be exploited through specially-crafted BGP messages that manipulate the AS-path attribute.
Yes, CVE-2010-1675 can be exploited remotely by a malicious BGP peer.