Denial of service in Quagga - CVE-2017-16227
Published: February 19, 2018
Vulnerability identifier: #VU10654
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16227
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the Quagga BGP daemon due to AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message. A remote attacker can іsupply specially crafted BGP UPDATE messages and cause session drop.
The weakness exists in the Quagga BGP daemon due to AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message. A remote attacker can іsupply specially crafted BGP UPDATE messages and cause session drop.
Affected software
Quagga
Arch Linux
Debian Linux
SUSE OpenStack Cloud
SUSE Linux
Ubuntu
Fedora
quagga (Alpine package)
quagga
Arch Linux
Debian Linux
SUSE OpenStack Cloud
SUSE Linux
Ubuntu
Fedora
quagga (Alpine package)
quagga
How to mitigate CVE-2017-16227
Update to version 1.2.2.
quagga (Alpine package) - update to 0.99.24.1-r6
quagga - addressed in versions 1.2.2-1.fc26, 1.2.2-1.fc27
quagga - addressed in versions 1.2.2-1.fc26, 1.2.2-1.fc27