CVE-2011-3326: Medium severity quagga routing software suite vulnerability
Published Oct 10, 2011
·Updated
The ospfflood function in ospfflood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update message.
Affected Software
38 affected components
Quagga Quagga=0.99.11
Quagga Quagga=0.99.2
Quagga Quagga=0.97.5
Quagga Quagga=0.95
Quagga Quagga=0.98.3
Quagga Quagga=0.96.3
Quagga Quagga=0.99.4
Quagga Quagga=0.99.7
Quagga Quagga=0.99.14
Quagga Quagga=0.99.5
Quagga Quagga=0.96.5
Quagga Quagga=0.98.0
Quagga Quagga=0.99.16
Quagga Quagga=0.96.1
Quagga Quagga=0.98.1
Quagga Quagga=0.96.4
Quagga Quagga=0.98.5
Quagga Quagga=0.97.3
Quagga Quagga=0.99.17
Quagga Quagga=0.99.3
Quagga Quagga=0.99.13
Quagga Quagga=0.99.6
Quagga Quagga=0.98.6
Quagga Quagga=0.97.4
Quagga Quagga=0.98.4
Quagga Quagga=0.99.12
Quagga Quagga=0.98.2
Quagga Quagga=0.97.1
Quagga Quagga=0.97.0
Quagga Quagga=0.96.2
Quagga Quagga=0.99.9
Quagga Quagga=0.99.1
Quagga Quagga<=0.99.18
Quagga Quagga=0.97.2
Quagga Quagga=0.99.15
Quagga Quagga=0.99.10
Quagga Quagga=0.99.8
Quagga Quagga=0.96
Remediation
Event History
Oct 10, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3326?
CVE-2011-3326 has a severity rating that indicates it can lead to a denial of service by crashing the ospfd daemon.
2
How do I fix CVE-2011-3326?
To fix CVE-2011-3326, you should upgrade to Quagga versions 0.99.19 or later.
3
What versions of Quagga are affected by CVE-2011-3326?
CVE-2011-3326 affects Quagga versions from 0.95 to 0.99.18.
4
What impact does CVE-2011-3326 have on my system?
CVE-2011-3326 can cause the ospfd daemon to crash, disrupting routing services.
5
Who can exploit CVE-2011-3326?
CVE-2011-3326 can be exploited by remote attackers who send specially crafted Link State Update messages.