Quagga Bugs Let Remote Users Obtain or Modify Routing Information and Local Users Deny Service
|
|
SecurityTracker Alert ID: 1016204
|
|
SecurityTracker URL: http://securitytracker.com/id?1016204
|
|
CVE Reference: CVE-2006-2223
, CVE-2006-2224
, CVE-2006-2276
(Links to External Site)
|
|
OSVDB Reference: 25224
, 25225
, 25245
(Links to External Site)
|
Date: Jun 2 2006
|
Impact: Denial of service via local system, Disclosure of system information, Modification of system information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 0.98.6
|
Description: Several vulnerabilities were reported in Quagga. A remote user can obtain sensitive routing information and modify routes. A local user can cause denial of service conditions.
RIPD does not properly validate or authenticate route table broadcasts [CVE-2006-2223]. A remote user can send a REQUEST packets
to obtain potentially sensitive information (e.g., routing state). Konstantin V. Gavrilenko of Arhont Ltd reported this vulnerability.
RIPD
does not properly enforce RIPv2 authentication requirements [CVE-2006-2224]. A remote user can send a RIPv1 RESPONSE packet to
modify the routing state (and inject routes). Konstantin V. Gavrilenko of Arhont Ltd reported this vulnerability.
A local user
can invoke a certain sh ip bgp command via the telnet interface to cause excessive CPU consumption [CVE-2006-2276]. Fredrik Widell
reported this vulnerability.
|
Impact: A remote user can obtain sensitive routing information and modify routes.
A local user can cause denial of service conditions.
|
Solution: The vendor has issued a fixed version (0.98.6 and 0.99.4).
The vendor's notice is available at:
http://lists.quagga.net/pipermail/quagga-users/2006-May/006874.html
|
Vendor URL: www.quagga.net/ (Links to External Site)
|
Cause: Authentication error, Exception handling error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 1 Jun 2006 23:15:55 -0400
Subject: Quagga vulnerabilities
|
CVE-2006-2223 CVE-2006-2224 CVE-2006-2276
|
|