ID

VAR-200605-0497


CVE

CVE-2006-2224


TITLE

Quagga RIPd Route Injection Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2006-2925 // CNNVD: CNNVD-200605-090

DESCRIPTION

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets. ------------ This vulnerability information is a summary of multiple vulnerabilities released at the same time. Please note that the contents of vulnerability information other than the title are included. ------------ Quagga , GNU Zebra Is TCP/IP A collection of daemons that support base routing related protocols. Out of them RIP , BGP As a daemon that handles the protocol RIPd , bgpd Is included. Quagga , GNU Zebra Has several security issues: 1) RIPd The daemon RIPv2 Even if the setting is valid only, regardless of the presence or absence of authentication RIPv1 There is a problem that responds to the request. (CVE-2006-2223) If exploited by a remote attacker, SEND UPDATE Such as REQUEST Routing information may be obtained illegally by using packets. 2) RIPd The daemon RIPv2 Despite being enabled for authentication, RIPv1 There is a problem of accepting packets without authentication. 3) bgpd Daemon community_str2com() There are deficiencies in the function, Telnet From the management interface show ip bgp If you execute the command, you will end up in an infinite loop CPU There is a problem that consumes resources. (CVE-2006-2276) If exploited by a local attacker, the target system can eventually become unserviceable.Please refer to the “Overview” for the impact of this vulnerability. Quagga is susceptible to remote information-disclosure and route-injection vulnerabilities. The application fails to properly ensure that required authentication and protocol configuration options are enforced. These issues allow remote attackers to gain access to potentially sensitive network-routing configuration information and to inject arbitrary routes into the RIP routing table. This may aid malicious users in further attacks against targeted networks. Quagga versions 0.98.5 and 0.99.3 are vulnerable to these issues; other versions may also be affected. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA 1059-1 security@debian.org http://www.debian.org/security/ Martin Schulze May 19th, 2006 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : quagga Vulnerability : several Problem type : remote Debian-specific: no CVE IDs : CVE-2006-2223 CVE-2006-2224 CVE-2006-2276 BugTraq ID : 17808 Debian Bugs : 365940 366980 Konstantin Gavrilenko discovered several vulnerabilities in quagga, the BGP/OSPF/RIP routing daemon. CVE-2006-2276 Fredrik Widell discovered that local users are can cause a denial of service ia a certain sh ip bgp command entered in the telnet interface. The old stable distribution (woody) does not contain quagga packages. For the stable distribution (sarge) these problems have been fixed in version 0.98.3-7.2. For the unstable distribution (sid) these problems have been fixed in version 0.99.4-1. We recommend that you upgrade your quagga package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2.dsc Size/MD5 checksum: 725 e985734e8ee31a87ff96f9c9b7291fa5 http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2.diff.gz Size/MD5 checksum: 43801 fe5b28230c268fe7ab141453a82c473c http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3.orig.tar.gz Size/MD5 checksum: 2118348 68be5e911e4d604c0f5959338263356e Architecture independent components: http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.98.3-7.2_all.deb Size/MD5 checksum: 488700 c79865480dfe140b106d39111b5379ba Alpha architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_alpha.deb Size/MD5 checksum: 1611704 c44bc78a27990ca9d77fe4529c04e42a AMD64 architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_amd64.deb Size/MD5 checksum: 1412990 7ab17ec568d3f0e2122677e81db5a2e2 ARM architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_arm.deb Size/MD5 checksum: 1290442 9a5d285ffe43d8b05c470147c48357d5 Intel IA-32 architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_i386.deb Size/MD5 checksum: 1191426 a0438042e1935582b66a44f17e62b40b Intel IA-64 architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_ia64.deb Size/MD5 checksum: 1829114 9e6e40afc51734c572de0f4e6e2d6519 HP Precision architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_hppa.deb Size/MD5 checksum: 1447726 4f6d058646cd78f86994eee61359df22 Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_m68k.deb Size/MD5 checksum: 1159670 1438a6da0f5c0672075438df92e82695 Big endian MIPS architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_mips.deb Size/MD5 checksum: 1352522 567e463657f21ec64870c1a243012b49 Little endian MIPS architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_mipsel.deb Size/MD5 checksum: 1355460 3dec77ae54b897882091bb5501b349c7 PowerPC architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_powerpc.deb Size/MD5 checksum: 1316776 adaa0828d830d7145236ee2f216fe46d IBM S/390 architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_s390.deb Size/MD5 checksum: 1401616 41b91f2eb90d26b1482696681552d9cb Sun Sparc architecture: http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_sparc.deb Size/MD5 checksum: 1287378 3b1624ec028e9f7944edd3fc396b0778 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iD8DBQFEbehrW5ql+IAeqTIRAu1bAJ0YQwvwCvugopyXVBCit2SwrYl+SACdF09d ELcxVZUFQP8s43SsJQ3mlqo= =Niwk -----END PGP SIGNATURE----- . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Quagga Routing Suite: Multiple vulnerabilities Date: May 21, 2006 Bugs: #132353 ID: 200605-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Quagga's RIP daemon allows the injection of routes and the disclosure of routing information. The BGP daemon is vulnerable to a Denial of Service. Background ========== The Quagga Routing Suite implements three major routing protocols: RIP (v1/v2/v3), OSPF (v2/v3) and BGP4. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/quagga < 0.98.6-r1 >= 0.98.6-r1 Description =========== Konstantin V. Gavrilenko discovered two flaws in the Routing Information Protocol (RIP) daemon that allow the processing of RIP v1 packets (carrying no authentication) even when the daemon is configured to use MD5 authentication or, in another case, even if RIP v1 is completely disabled. Workaround ========== There is no known workaround at this time. Resolution ========== All Quagga users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/quagga-0.98.6-r1" References ========== [ 1 ] CVE-2006-2223 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223 [ 2 ] CVE-2006-2224 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2224 [ 3 ] CVE-2006-2276 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2276 [ 4 ] Official release information http://www.quagga.net/news2.php?y=2006&m=5&d=8#id1147115280 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200605-15.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. License ======= Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5

Trust: 2.61

sources: NVD: CVE-2006-2224 // JVNDB: JVNDB-2006-000260 // CNVD: CNVD-2006-2925 // BID: 17808 // PACKETSTORM: 46498 // PACKETSTORM: 46526

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2006-2925

AFFECTED PRODUCTS

vendor:quaggamodel:routing software suitescope:eqversion:0.98.5

Trust: 1.9

vendor:quaggamodel:routing software suitescope:eqversion:0.96.3

Trust: 1.6

vendor:quaggamodel:routing software suitescope:eqversion:0.95

Trust: 1.6

vendor:quaggamodel:routing software suitescope:eqversion:0.96.2

Trust: 1.6

vendor:quaggamodel:routing software suitescope:lteversion:0.99.3

Trust: 1.0

vendor:quaggamodel:routing software suitescope:eqversion:0.99.3

Trust: 0.9

vendor:cybertrustmodel:asianux serverscope:eqversion:4.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:4.0 (x86-64)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:2.1 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:3 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:3 (es)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (es)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:4 (ws)

Trust: 0.8

vendor:quaggamodel:routing software suite quaggascope:eqversion:0.95

Trust: 0.6

vendor:quaggamodel:routing software suite quaggascope:eqversion:0.96.2

Trust: 0.6

vendor:quaggamodel:routing software suite quaggascope:eqversion:0.96.3

Trust: 0.6

vendor:quaggamodel:routing software suite quaggascope:eqversion:0.98.5

Trust: 0.6

vendor:quaggamodel:routing software suite quaggascope:eqversion:0.99.3

Trust: 0.6

vendor:ubuntumodel:linux powerpcscope:eqversion:5.10

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:5.10

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:5.10

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:5.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:5.04

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:5.04

Trust: 0.3

vendor:trustixmodel:secure linuxscope:eqversion:3.0

Trust: 0.3

vendor:susemodel:linux enterprise serverscope:eqversion:9

Trust: 0.3

vendor:susemodel:linux enterprise serverscope:eqversion:10

Trust: 0.3

vendor:susemodel:linux enterprise desktopscope:eqversion:10

Trust: 0.3

vendor:sgimodel:propack sp6scope:eqversion:3.0

Trust: 0.3

vendor:s u s emodel:unitedlinuxscope:eqversion:1.0

Trust: 0.3

vendor:s u s emodel:suse linux standard serverscope:eqversion:8.0

Trust: 0.3

vendor:s u s emodel:suse linux school server for i386scope: - version: -

Trust: 0.3

vendor:s u s emodel:suse linux retail solutionscope:eqversion:8.0

Trust: 0.3

vendor:s u s emodel:suse linux openexchange serverscope:eqversion:4.0

Trust: 0.3

vendor:s u s emodel:suse linux open-xchangescope:eqversion:4.1

Trust: 0.3

vendor:s u s emodel:open-enterprise-serverscope:eqversion:9.0

Trust: 0.3

vendor:s u s emodel:open-enterprise-serverscope:eqversion:1

Trust: 0.3

vendor:s u s emodel:office serverscope: - version: -

Trust: 0.3

vendor:s u s emodel:novell linux desktopscope:eqversion:9.0

Trust: 0.3

vendor:s u s emodel:novell linux desktopscope:eqversion:1.0

Trust: 0.3

vendor:s u s emodel:linux professional ossscope:eqversion:10.0

Trust: 0.3

vendor:s u s emodel:linux professionalscope:eqversion:10.0

Trust: 0.3

vendor:s u s emodel:linux professional x86 64scope:eqversion:9.3

Trust: 0.3

vendor:s u s emodel:linux professionalscope:eqversion:9.3

Trust: 0.3

vendor:s u s emodel:linux professional x86 64scope:eqversion:9.2

Trust: 0.3

vendor:s u s emodel:linux professionalscope:eqversion:9.2

Trust: 0.3

vendor:s u s emodel:linux professional x86 64scope:eqversion:9.1

Trust: 0.3

vendor:s u s emodel:linux professionalscope:eqversion:9.1

Trust: 0.3

vendor:s u s emodel:linux professionalscope:eqversion:10.1

Trust: 0.3

vendor:s u s emodel:linux personal ossscope:eqversion:10.0

Trust: 0.3

vendor:s u s emodel:linux personal x86 64scope:eqversion:9.3

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:9.3

Trust: 0.3

vendor:s u s emodel:linux personal x86 64scope:eqversion:9.2

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:9.2

Trust: 0.3

vendor:s u s emodel:linux personal x86 64scope:eqversion:9.1

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:9.1

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:10.1

Trust: 0.3

vendor:s u s emodel:linux enterprise server for s/390scope:eqversion:9.0

Trust: 0.3

vendor:s u s emodel:linux enterprise server for s/390scope: - version: -

Trust: 0.3

vendor:redhatmodel:enterprise linux wsscope:eqversion:4

Trust: 0.3

vendor:redhatmodel:enterprise linux wsscope:eqversion:3

Trust: 0.3

vendor:redhatmodel:enterprise linux esscope:eqversion:4

Trust: 0.3

vendor:redhatmodel:enterprise linux esscope:eqversion:3

Trust: 0.3

vendor:redhatmodel:desktopscope:eqversion:4.0

Trust: 0.3

vendor:redhatmodel:desktopscope:eqversion:3.0

Trust: 0.3

vendor:redhatmodel:advanced workstation for the itanium processor ia64scope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:advanced workstation for the itanium processorscope:eqversion:2.1

Trust: 0.3

vendor:redmodel:hat enterprise linux asscope:eqversion:4

Trust: 0.3

vendor:redmodel:hat enterprise linux asscope:eqversion:3

Trust: 0.3

vendor:redmodel:hat enterprise linux as ia64scope:eqversion:2.1

Trust: 0.3

vendor:redmodel:hat enterprise linux asscope:eqversion:2.1

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.97.3

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux ppcscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux mipselscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux m68kscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux hppascope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linux alphascope:eqversion:3.1

Trust: 0.3

vendor:debianmodel:linuxscope:eqversion:3.1

Trust: 0.3

sources: CNVD: CNVD-2006-2925 // BID: 17808 // JVNDB: JVNDB-2006-000260 // CNNVD: CNNVD-200605-090 // NVD: CVE-2006-2224

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-2224
value: MEDIUM

Trust: 1.0

NVD: CVE-2006-2224
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2006-2925
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-200605-090
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2006-2224
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2006-2925
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2006-2925 // JVNDB: JVNDB-2006-000260 // CNNVD: CNNVD-200605-090 // NVD: CVE-2006-2224

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.0

sources: NVD: CVE-2006-2224

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200605-090

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-200605-090

CONFIGURATIONS

sources: JVNDB: JVNDB-2006-000260

PATCH

title:quaggaurl:http://www.miraclelinux.com/support/update/list.php?errata_id=396

Trust: 0.8

title:RHSA-2006:0533url:https://rhn.redhat.com/errata/RHSA-2006-0533.html

Trust: 0.8

title:RHSA-2006:0525url:https://rhn.redhat.com/errata/RHSA-2006-0525.html

Trust: 0.8

title:RHSA-2006:0533url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2006-0533J.html

Trust: 0.8

title:RHSA-2006:0525url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2006-0525J.html

Trust: 0.8

title:Patch for Quagga RIPd Route Injection Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/40797

Trust: 0.6

sources: CNVD: CNVD-2006-2925 // JVNDB: JVNDB-2006-000260

EXTERNAL IDS

db:NVDid:CVE-2006-2224

Trust: 3.5

db:BIDid:17808

Trust: 3.3

db:SECUNIAid:19910

Trust: 2.4

db:SECTRACKid:1016204

Trust: 1.6

db:SECUNIAid:20221

Trust: 1.6

db:SECUNIAid:20137

Trust: 1.6

db:SECUNIAid:21159

Trust: 1.6

db:SECUNIAid:20421

Trust: 1.6

db:SECUNIAid:20782

Trust: 1.6

db:SECUNIAid:20138

Trust: 1.6

db:SECUNIAid:20420

Trust: 1.6

db:OSVDBid:25225

Trust: 1.6

db:BIDid:17979

Trust: 0.8

db:SECUNIAid:20116

Trust: 0.8

db:JVNDBid:JVNDB-2006-000260

Trust: 0.8

db:CNVDid:CNVD-2006-2925

Trust: 0.6

db:UBUNTUid:USN-284-1

Trust: 0.6

db:SUSEid:SUSE-SR:2006:017

Trust: 0.6

db:XFid:1

Trust: 0.6

db:XFid:26251

Trust: 0.6

db:GENTOOid:GLSA-200605-15

Trust: 0.6

db:REDHATid:RHSA-2006:0525

Trust: 0.6

db:REDHATid:RHSA-2006:0533

Trust: 0.6

db:DEBIANid:DSA-1059

Trust: 0.6

db:BUGTRAQid:20060503 RE: QUAGGA RIPD UNAUTHENTICATED ROUTE INJECTION

Trust: 0.6

db:BUGTRAQid:20060503 QUAGGA RIPD UNAUTHENTICATED ROUTE INJECTION

Trust: 0.6

db:SGIid:20060602-01-U

Trust: 0.6

db:CNNVDid:CNNVD-200605-090

Trust: 0.6

db:PACKETSTORMid:46498

Trust: 0.1

db:PACKETSTORMid:46526

Trust: 0.1

sources: CNVD: CNVD-2006-2925 // BID: 17808 // JVNDB: JVNDB-2006-000260 // PACKETSTORM: 46498 // PACKETSTORM: 46526 // CNNVD: CNNVD-200605-090 // NVD: CVE-2006-2224

REFERENCES

url:http://www.securityfocus.com/bid/17808

Trust: 3.0

url:http://bugzilla.quagga.net/show_bug.cgi?id=262

Trust: 1.9

url:http://secunia.com/advisories/19910

Trust: 1.6

url:http://www.redhat.com/support/errata/rhsa-2006-0533.html

Trust: 1.6

url:http://www.redhat.com/support/errata/rhsa-2006-0525.html

Trust: 1.6

url:http://www.osvdb.org/25225

Trust: 1.6

url:http://www.novell.com/linux/security/advisories/2006_17_sr.html

Trust: 1.6

url:http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml

Trust: 1.6

url:http://www.debian.org/security/2006/dsa-1059

Trust: 1.6

url:http://securitytracker.com/id?1016204

Trust: 1.6

url:http://secunia.com/advisories/21159

Trust: 1.6

url:http://secunia.com/advisories/20782

Trust: 1.6

url:http://secunia.com/advisories/20421

Trust: 1.6

url:http://secunia.com/advisories/20420

Trust: 1.6

url:http://secunia.com/advisories/20221

Trust: 1.6

url:http://secunia.com/advisories/20138

Trust: 1.6

url:http://secunia.com/advisories/20137

Trust: 1.6

url:ftp://patches.sgi.com/support/free/security/advisories/20060602-01-u.asc

Trust: 1.6

url:http://www.securityfocus.com/archive/1/432823/100/0/threaded

Trust: 1.0

url:http://www.securityfocus.com/archive/1/432856/100/0/threaded

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/26251

Trust: 1.0

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a10775

Trust: 1.0

url:https://usn.ubuntu.com/284-1/

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-2224

Trust: 0.9

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2006-2224

Trust: 0.8

url:http://secunia.com/advisories/20116/

Trust: 0.8

url:http://secunia.com/advisories/19910/

Trust: 0.8

url:http://www.securityfocus.com/bid/17979

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/432856/100/0/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/432823/100/0/threaded

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/26251

Trust: 0.6

url:http://www.ubuntulinux.org/support/documentation/usn/usn-284-1

Trust: 0.6

url:http://bugzilla.quagga.net/show_bug.cgi?id=261

Trust: 0.3

url:http://www.quagga.net/

Trust: 0.3

url:http://rhn.redhat.com/errata/rhsa-2006-0525.html

Trust: 0.3

url:http://rhn.redhat.com/errata/rhsa-2006-0533.html

Trust: 0.3

url:/archive/1/432856

Trust: 0.3

url:/archive/1/432822

Trust: 0.3

url:/archive/1/432823

Trust: 0.3

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2.dsc

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-2224

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2.diff.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga-doc_0.98.3-7.2_all.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3.orig.tar.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_amd64.deb

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-2223

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_mipsel.deb

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-2276

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_alpha.deb

Trust: 0.1

url:http://packages.debian.org/<pkg>

Trust: 0.1

url:http://security.debian.org/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_m68k.deb

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/q/quagga/quagga_0.98.3-7.2_powerpc.deb

Trust: 0.1

url:http://bugs.gentoo.org.

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-2223

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-200605-15.xml

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://www.quagga.net/news2.php?y=2006&m=5&d=8#id1147115280

Trust: 0.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-2276

Trust: 0.1

sources: CNVD: CNVD-2006-2925 // BID: 17808 // JVNDB: JVNDB-2006-000260 // PACKETSTORM: 46498 // PACKETSTORM: 46526 // CNNVD: CNNVD-200605-090 // NVD: CVE-2006-2224

CREDITS

Konstantin V. Gavrilenko discovered these vulnerabilities.

Trust: 0.9

sources: BID: 17808 // CNNVD: CNNVD-200605-090

SOURCES

db:CNVDid:CNVD-2006-2925
db:BIDid:17808
db:JVNDBid:JVNDB-2006-000260
db:PACKETSTORMid:46498
db:PACKETSTORMid:46526
db:CNNVDid:CNNVD-200605-090
db:NVDid:CVE-2006-2224

LAST UPDATE DATE

2024-09-15T22:49:47.037000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2006-2925date:2006-05-05T00:00:00
db:BIDid:17808date:2015-03-19T09:41:00
db:JVNDBid:JVNDB-2006-000260date:2007-04-01T00:00:00
db:CNNVDid:CNNVD-200605-090date:2006-05-08T00:00:00
db:NVDid:CVE-2006-2224date:2018-10-18T16:38:43.053

SOURCES RELEASE DATE

db:CNVDid:CNVD-2006-2925date:2006-05-05T00:00:00
db:BIDid:17808date:2006-05-03T00:00:00
db:JVNDBid:JVNDB-2006-000260date:2007-04-01T00:00:00
db:PACKETSTORMid:46498date:2006-05-22T06:20:21
db:PACKETSTORMid:46526date:2006-05-22T07:26:25
db:CNNVDid:CNNVD-200605-090date:2006-05-05T00:00:00
db:NVDid:CVE-2006-2224date:2006-05-05T19:02:00