CVE-2018-5380: Medium severity Quagga Quagga vulnerability
Last updated 25 August 2025
Other sources
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
quagga/bgpdto a version that resolves this vulnerability.Fixed in 1.2.3
Event History
Frequently Asked Questions
What is CVE-2018-5380?
CVE-2018-5380 is a vulnerability in the Quagga BGP daemon (bgpd) prior to version 1.2.3 that can overrun internal BGP code-to-string conversion tables used for debug.
What is the severity of CVE-2018-5380?
The severity of CVE-2018-5380 is medium with a CVSS score of 4.3.
How does CVE-2018-5380 affect Quagga?
CVE-2018-5380 affects Quagga versions prior to 1.2.3.
Where can I find more information about CVE-2018-5380?
You can find more information about CVE-2018-5380 at the following references: [link1](http://savannah.nongnu.org/forum/forum.php?forum_id=9095), [link2](http://www.kb.cert.org/vuls/id/940439), [link3](https://cert-portal.siemens.com/productcert/pdf/ssa-451142.pdf).
How do I fix CVE-2018-5380 in Quagga?
To fix CVE-2018-5380 in Quagga, you need to update to version 1.2.3 or later.