Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

31 – 40 of 56 results


CVE-2016-4049

Medium priority

Some fixes available 3 of 4

The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP packet.

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga Fixed
Show less packages

CVE-2016-4036

Low priority

Some fixes available 3 of 4

The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directory.

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga Fixed
Show less packages

CVE-2016-2342

High priority
Fixed

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2013-6051

Low priority
Ignored

The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update.

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2013-2236

Low priority

Some fixes available 1 of 5

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2012-1820

Medium priority

Some fixes available 4 of 5

The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2012-0255

Medium priority

Some fixes available 4 of 6

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2012-0250

Medium priority

Some fixes available 4 of 6

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2012-0249

Medium priority

Some fixes available 4 of 6

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages

CVE-2011-3327

Medium priority

Some fixes available 4 of 5

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending...

1 affected packages

quagga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
quagga
Show less packages