CVE-2012-1820: Low severity Quagga Quagga vulnerability
The bgpcapabilityorf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1820?
CVE-2012-1820 has a severity that can lead to denial of service due to an assertion failure and daemon exit.
How do I fix CVE-2012-1820?
To fix CVE-2012-1820, upgrade Quagga to version 0.99.21 or later.
Which software versions are affected by CVE-2012-1820?
CVE-2012-1820 affects Quagga versions up to and including 0.99.20.1 and specific earlier versions.
What kind of attack does CVE-2012-1820 exploit?
CVE-2012-1820 is exploited by sending a malformed Outbound Route Filtering capability TLV in a BGP OPEN message.
Can I still use Quagga if I have CVE-2012-1820?
Using Quagga versions affected by CVE-2012-1820 is risky as it could lead to service disruption unless patched.