Denial of service in Quagga - CVE-2017-16227

 

Denial of service in Quagga - CVE-2017-16227

Published: February 19, 2018


Vulnerability identifier: #VU10654
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16227
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the Quagga BGP daemon due to AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message. A remote attacker can іsupply specially crafted BGP UPDATE messages and cause session drop.

Affected software

Quagga
Arch Linux
Debian Linux
SUSE OpenStack Cloud
SUSE Linux
Ubuntu
Fedora
quagga (Alpine package)
quagga

How to mitigate CVE-2017-16227

Update to version 1.2.2.

quagga (Alpine package) - update to 0.99.24.1-r6
quagga - addressed in versions 1.2.2-1.fc26, 1.2.2-1.fc27

External References

Related Security Bulletins