First published: Wed Sep 14 2011(Updated: )
A denial of service flaw was found in the way the ospfd daemon of the Quagga routing suire processes malformed Hello packets (not complete Hello packets of Hello packets with invalid OSPFv2 header type). A configured OSPF peer, could use this flaw to cause the master OSPF daemon (ospfd) to crash.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/quagga | <0:0.98.6-7.el5_8.1 | 0:0.98.6-7.el5_8.1 |
redhat/quagga | <0:0.99.15-7.el6_3.2 | 0:0.99.15-7.el6_3.2 |
redhat/quagga | <0.99.19 | 0.99.19 |
Quagga Routing Software Suite | <=0.99.18 | |
Quagga Routing Software Suite | =0.95 | |
Quagga Routing Software Suite | =0.96 | |
Quagga Routing Software Suite | =0.96.1 | |
Quagga Routing Software Suite | =0.96.2 | |
Quagga Routing Software Suite | =0.96.3 | |
Quagga Routing Software Suite | =0.96.4 | |
Quagga Routing Software Suite | =0.96.5 | |
Quagga Routing Software Suite | =0.97.0 | |
Quagga Routing Software Suite | =0.97.1 | |
Quagga Routing Software Suite | =0.97.2 | |
Quagga Routing Software Suite | =0.97.3 | |
Quagga Routing Software Suite | =0.97.4 | |
Quagga Routing Software Suite | =0.97.5 | |
Quagga Routing Software Suite | =0.98.0 | |
Quagga Routing Software Suite | =0.98.1 | |
Quagga Routing Software Suite | =0.98.2 | |
Quagga Routing Software Suite | =0.98.3 | |
Quagga Routing Software Suite | =0.98.4 | |
Quagga Routing Software Suite | =0.98.5 | |
Quagga Routing Software Suite | =0.98.6 | |
Quagga Routing Software Suite | =0.99.1 | |
Quagga Routing Software Suite | =0.99.2 | |
Quagga Routing Software Suite | =0.99.3 | |
Quagga Routing Software Suite | =0.99.4 | |
Quagga Routing Software Suite | =0.99.5 | |
Quagga Routing Software Suite | =0.99.6 | |
Quagga Routing Software Suite | =0.99.7 | |
Quagga Routing Software Suite | =0.99.8 | |
Quagga Routing Software Suite | =0.99.9 | |
Quagga Routing Software Suite | =0.99.10 | |
Quagga Routing Software Suite | =0.99.11 | |
Quagga Routing Software Suite | =0.99.12 | |
Quagga Routing Software Suite | =0.99.13 | |
Quagga Routing Software Suite | =0.99.14 | |
Quagga Routing Software Suite | =0.99.15 | |
Quagga Routing Software Suite | =0.99.16 | |
Quagga Routing Software Suite | =0.99.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3325 is classified as a denial of service vulnerability due to its ability to crash the ospfd daemon.
To fix CVE-2011-3325, update the Quagga routing software to versions 0.99.19 or higher, or 0:0.98.6-7.el5_8.1, or 0:0.99.15-7.el6_3.2.
CVE-2011-3325 affects multiple versions of Quagga up to 0.99.18, including versions 0.95 through 0.99.18.
A configured OSPF peer can exploit CVE-2011-3325 by sending malformed Hello packets to the ospfd daemon.
Any system running vulnerable versions of the Quagga routing software is susceptible to CVE-2011-3325.