>> Quagga bgpd Daemon "UPDATE" Message Processing Denial of Service Vulnerability
Title : Quagga bgpd Daemon "UPDATE" Message Processing Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1336 CVE ID : CVE-2007-1995
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-11
Technical Description
A vulnerability has been identified in Quagga, which could be exploited by remote attackers to cause a denial of service. This issue is caused by errors in the BGP attributes management routines (bgpd/bgp_attr.c) that fail to properly validate length information read from the "MP_REACH_NLRI" and "MP_UNREACH_NLRI" attributes, which could be exploited by a malicious configured peer to create a denial of service condition by sending a specially crafted "UPDATE" message.