Double free memory error in Quagga - CVE-2018-5379
Published: February 16, 2018
Vulnerability identifier: #VU10612
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5379
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the Quagga BGP daemon due to double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A remote attacker can supply specially crafted input, trigger bqpd to crash and execute arbitrary code.
The weakness exists in the Quagga BGP daemon due to double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A remote attacker can supply specially crafted input, trigger bqpd to crash and execute arbitrary code.
Affected software
Quagga
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Fedora
libfpm_pb0-debuginfo
libzebra1
quagga-debugsource
libfpm_pb0
libzebra1-debuginfo
libospfapiclient0
quagga-debuginfo
libquagga_pb0-debuginfo
libospf0
libospfapiclient0-debuginfo
libquagga_pb0
quagga
libospf0-debuginfo
quagga-devel
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Fedora
libfpm_pb0-debuginfo
libzebra1
quagga-debugsource
libfpm_pb0
libzebra1-debuginfo
libospfapiclient0
quagga-debuginfo
libquagga_pb0-debuginfo
libospf0
libospfapiclient0-debuginfo
libquagga_pb0
quagga
libospf0-debuginfo
quagga-devel
How to mitigate CVE-2018-5379
Update to version 1.2.3.
libfpm_pb0-debuginfo - update to 1.1.1-17.13.1
libzebra1 - update to 1.1.1-17.13.1
quagga-debugsource - update to 1.1.1-17.13.1
libfpm_pb0 - update to 1.1.1-17.13.1
libzebra1-debuginfo - update to 1.1.1-17.13.1
libospfapiclient0 - update to 1.1.1-17.13.1
quagga-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0-debuginfo - update to 1.1.1-17.13.1
libospf0 - update to 1.1.1-17.13.1
libospfapiclient0-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0 - update to 1.1.1-17.13.1
quagga - update to 1.1.1-17.13.1
libospf0-debuginfo - update to 1.1.1-17.13.1
quagga-devel - update to 1.1.1-17.13.1
quagga - addressed in versions 1.2.2-2.fc26, 1.2.2-2.fc27
libzebra1 - update to 1.1.1-17.13.1
quagga-debugsource - update to 1.1.1-17.13.1
libfpm_pb0 - update to 1.1.1-17.13.1
libzebra1-debuginfo - update to 1.1.1-17.13.1
libospfapiclient0 - update to 1.1.1-17.13.1
quagga-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0-debuginfo - update to 1.1.1-17.13.1
libospf0 - update to 1.1.1-17.13.1
libospfapiclient0-debuginfo - update to 1.1.1-17.13.1
libquagga_pb0 - update to 1.1.1-17.13.1
quagga - update to 1.1.1-17.13.1
libospf0-debuginfo - update to 1.1.1-17.13.1
quagga-devel - update to 1.1.1-17.13.1
quagga - addressed in versions 1.2.2-2.fc26, 1.2.2-2.fc27
External References
Related Security Bulletins
- Debian update for quagga
- Ubuntu update for Quagga
- Multiple vulnerabilities in Quagga
- SUSE Linux update for quagga
- SUSE Linux update for quagga
- Amazon Linux AMI update for quagga
- Red Hat update for quagga
- OpenSUSE Linux update for quagga
- Gentoo update for Quagga
- SUSE update for quagga
- Fedora 27 update for quagga
- Fedora 26 update for quagga