CVE-2012-0255: Buffer Overflow
The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0255?
CVE-2012-0255 is classified as a denial of service vulnerability due to improper handling of OPEN messages.
How do I fix CVE-2012-0255?
To fix CVE-2012-0255, upgrade Quagga to version 0.99.20.1 or later where the vulnerability is addressed.
Which versions of Quagga are affected by CVE-2012-0255?
CVE-2012-0255 affects Quagga versions prior to 0.99.20.1, including versions from 0.95 to 0.99.19.
What types of attacks can be executed through CVE-2012-0255?
Attackers can exploit CVE-2012-0255 to crash the bgpd daemon leading to a denial of service condition.
Who is primarily impacted by CVE-2012-0255?
Network administrators using affected versions of Quagga for BGP routing are primarily impacted by CVE-2012-0255.