CVE-2016-2342: Buffer Overflow
The bgpnlriparsevpnv4 function in bgpmplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2342?
CVE-2016-2342 has been classified with a high severity rating due to its potential for remote code execution.
How do I fix CVE-2016-2342?
To fix CVE-2016-2342, upgrade to a version of Quagga that is newer than 1.0.20160309.
Which versions of Quagga are affected by CVE-2016-2342?
CVE-2016-2342 affects Quagga versions before 1.0.20160309.
What types of attacks can CVE-2016-2342 enable?
CVE-2016-2342 can enable remote attackers to execute arbitrary code on the affected system.
Is there a patch available for CVE-2016-2342?
Yes, a patch is available in the form of updated versions of the Quagga software.