CVE-2021-44038: High severity quagga routing software suite vulnerability
Published Nov 19, 2021
·Updated
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.
Affected Software
2 affected componentsFixes available
Quagga Quagga<=1.2.4
Microsoft cbl2 quagga
Event History
Nov 19, 2021
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
Description
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2021-44038
2
What is the severity of CVE-2021-44038?
The severity of CVE-2021-44038 is high with a severity value of 7.8.
3
How does CVE-2021-44038 impact Quagga?
CVE-2021-44038 allows users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.
4
Which versions of Quagga are affected by CVE-2021-44038?
Quagga versions up to and including 1.2.4 are affected by CVE-2021-44038.
5
Are there any known fixes or patches available for CVE-2021-44038?
Yes, fixes for CVE-2021-44038 are available. Please refer to the references for more information.