SB2019090913 - Buffer overflow in BIRD Internet Routing Daemon
Published: September 9, 2019 Updated: September 29, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2019-16159)
The vulnerability allows a remote attacker to execute arbitrary code on the target system or perform denial of service attack.The vulnerability exists due to a boundary error when checking validity of BGP administrative shutdown communication messages. A remote unauthenticated attacker can send a specially crafted administrative shutdown communication message, trigger a four-byte stack-based buffer overflow and perform denial of service attack or execute arbitrary code on the target system.
Remediation
Install update from vendor's website.
References
- http://bird.network.cz
- http://trubka.network.cz/pipermail/bird-users/2019-September/013718.html
- http://trubka.network.cz/pipermail/bird-users/2019-September/013720.html
- http://trubka.network.cz/pipermail/bird-users/2019-September/013722.html
- https://gitlab.labs.nic.cz/labs/bird/commit/1657c41c96b3c07d9265b07dd4912033ead4124b
- https://gitlab.labs.nic.cz/labs/bird/commit/8388f5a7e14108a1458fea35bfbb5a453e2c563c