First published: Tue Aug 24 2010(Updated: )
A NULL pointer dereference flaw was found in the way Quagga's bgpd daemon parsed paths of autonomous systems (AS). A configured BGP peer could send a BGP update AS path request with unknown AS type, which could lead to denial of service (bgpd daemon crash). Upstream changeset: [1] <a href="http://code.quagga.net/?p=quagga.git;a=commit;h=cddb8112b80fa9867156c637d63e6e79eeac67bb">http://code.quagga.net/?p=quagga.git;a=commit;h=cddb8112b80fa9867156c637d63e6e79eeac67bb</a> References: [2] <a href="http://www.quagga.net/news2.php?y=2010&m=8&d=19#id1282241100">http://www.quagga.net/news2.php?y=2010&m=8&d=19#id1282241100</a> CVE Request: [3] <a href="http://www.openwall.com/lists/oss-security/2010/08/24/3">http://www.openwall.com/lists/oss-security/2010/08/24/3</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quagga Routing Software Suite | <=0.99.16 | |
Quagga Routing Software Suite | =0.95 | |
Quagga Routing Software Suite | =0.96 | |
Quagga Routing Software Suite | =0.96.1 | |
Quagga Routing Software Suite | =0.96.2 | |
Quagga Routing Software Suite | =0.96.3 | |
Quagga Routing Software Suite | =0.96.4 | |
Quagga Routing Software Suite | =0.96.5 | |
Quagga Routing Software Suite | =0.97.0 | |
Quagga Routing Software Suite | =0.97.1 | |
Quagga Routing Software Suite | =0.97.2 | |
Quagga Routing Software Suite | =0.97.3 | |
Quagga Routing Software Suite | =0.97.4 | |
Quagga Routing Software Suite | =0.97.5 | |
Quagga Routing Software Suite | =0.98.0 | |
Quagga Routing Software Suite | =0.98.1 | |
Quagga Routing Software Suite | =0.98.2 | |
Quagga Routing Software Suite | =0.98.3 | |
Quagga Routing Software Suite | =0.98.4 | |
Quagga Routing Software Suite | =0.98.5 | |
Quagga Routing Software Suite | =0.98.6 | |
Quagga Routing Software Suite | =0.99.1 | |
Quagga Routing Software Suite | =0.99.2 | |
Quagga Routing Software Suite | =0.99.3 | |
Quagga Routing Software Suite | =0.99.4 | |
Quagga Routing Software Suite | =0.99.5 | |
Quagga Routing Software Suite | =0.99.6 | |
Quagga Routing Software Suite | =0.99.7 | |
Quagga Routing Software Suite | =0.99.8 | |
Quagga Routing Software Suite | =0.99.9 | |
Quagga Routing Software Suite | =0.99.10 | |
Quagga Routing Software Suite | =0.99.11 | |
Quagga Routing Software Suite | =0.99.12 | |
Quagga Routing Software Suite | =0.99.13 | |
Quagga Routing Software Suite | =0.99.14 | |
Quagga Routing Software Suite | =0.99.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2949 has a severity of medium, as it can lead to denial of service due to a NULL pointer dereference.
To fix CVE-2010-2949, users should upgrade to a patched version of Quagga that addresses this vulnerability.
CVE-2010-2949 affects Quagga versions up to 0.99.16 and specific older versions, such as 0.95 to 0.98.x.
CVE-2010-2949 is classified as a NULL pointer dereference vulnerability in the BGP daemon of Quagga.
The impact of CVE-2010-2949 is a denial of service, as it can cause the bgpd daemon to crash.