ID

VAR-201204-0159


CVE

CVE-2012-0249


TITLE

Quagga contains multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#551715

DESCRIPTION

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header. Quagga, a routing software suite, contains multiple vulnerabilities that result in a denial-of-service condition. Quagga is prone to multiple remote security vulnerabilities including: 1. A denial-of-service vulnerability 2. Multiple buffer-overflow vulnerabilities An attackers can exploit these issues to execute arbitrary code in the context of the application or cause denial-of-service conditions. Quagga versions prior to 0.99.20.1 are vulnerable. ============================================================================ Ubuntu Security Notice USN-1441-1 May 15, 2012 quagga vulnerabilities ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS Summary: Quagga could be made to crash if it received specially crafted network traffic. (CVE-2012-0249, CVE-2012-0250) It was discovered that Quagga incorrectly handled messages with a malformed Four-octet AS Number Capability. After a standard system update you need to restart Quagga to make all the necessary changes. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: Debian update for quagga SECUNIA ADVISORY ID: SA48949 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/48949/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=48949 RELEASE DATE: 2012-04-26 DISCUSS ADVISORY: http://secunia.com/advisories/48949/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/48949/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=48949 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Debian has issued an update for quagga. This fixes multiple vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service). For more information: SA48388 SOLUTION: Apply updated packages via the apt-get package manager. ORIGINAL ADVISORY: DSA-2459-1: http://lists.debian.org/debian-security-announce/2012/msg00092.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201310-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Quagga: Multiple vulnerabilities Date: October 10, 2013 Bugs: #408507, #475706 ID: 201310-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in Quagga, the worst of which could lead to arbitrary code execution. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Quagga users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/quagga-0.99.22.4" References ========== [ 1 ] CVE-2012-0249 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0249 [ 2 ] CVE-2012-0250 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0250 [ 3 ] CVE-2012-0255 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0255 [ 4 ] CVE-2012-1820 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1820 [ 5 ] CVE-2013-2236 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2236 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201310-08.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2013 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: quagga security update Advisory ID: RHSA-2012:1259-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-1259.html Issue date: 2012-09-12 CVE Names: CVE-2011-3323 CVE-2011-3324 CVE-2011-3325 CVE-2011-3326 CVE-2011-3327 CVE-2012-0249 CVE-2012-0250 CVE-2012-0255 CVE-2012-1820 ===================================================================== 1. Summary: Updated quagga packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. The Quagga bgpd daemon implements the BGP (Border Gateway Protocol) routing protocol. The Quagga ospfd and ospf6d daemons implement the OSPF (Open Shortest Path First) routing protocol. A heap-based buffer overflow flaw was found in the way the bgpd daemon processed malformed Extended Communities path attributes. An attacker could send a specially-crafted BGP message, causing bgpd on a target system to crash or, possibly, execute arbitrary code with the privileges of the user running bgpd. The UPDATE message would have to arrive from an explicitly configured BGP peer, but could have originated elsewhere in the BGP network. An OSPF router could use this flaw to crash ospf6d on an adjacent router. (CVE-2011-3323) A flaw was found in the way the ospf6d daemon processed malformed link state advertisements. An OSPF neighbor could use this flaw to crash ospf6d on a target system. (CVE-2011-3324) A flaw was found in the way the ospfd daemon processed malformed Hello packets. An OSPF neighbor could use this flaw to crash ospfd on a target system. (CVE-2011-3325) A flaw was found in the way the ospfd daemon processed malformed link state advertisements. An OSPF router in the autonomous system could use this flaw to crash ospfd on a target system. An OSPF router could use this flaw to cause ospfd on an adjacent router to abort. An OSPF router could use this flaw to crash ospfd on an adjacent router. (CVE-2012-0250) Two flaws were found in the way the bgpd daemon processed certain BGP OPEN messages. A configured BGP peer could cause bgpd on a target system to abort via a specially-crafted BGP OPEN message. (CVE-2012-0255, CVE-2012-1820) Red Hat would like to thank CERT-FI for reporting CVE-2011-3327, CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326; and the CERT/CC for reporting CVE-2012-0249, CVE-2012-0250, CVE-2012-0255, and CVE-2012-1820. CERT-FI acknowledges Riku Hietamäki, Tuomo Untinen and Jukka Taimisto of the Codenomicon CROSS project as the original reporters of CVE-2011-3327, CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326. The CERT/CC acknowledges Martin Winter at OpenSourceRouting.org as the original reporter of CVE-2012-0249, CVE-2012-0250, and CVE-2012-0255, and Denis Ovsienko as the original reporter of CVE-2012-1820. Users of quagga should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the bgpd, ospfd, and ospf6d daemons will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Package List: Red Hat Enterprise Linux Server (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/quagga-0.99.15-7.el6_3.2.src.rpm i386: quagga-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm ppc64: quagga-0.99.15-7.el6_3.2.ppc64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.ppc64.rpm s390x: quagga-0.99.15-7.el6_3.2.s390x.rpm quagga-debuginfo-0.99.15-7.el6_3.2.s390x.rpm x86_64: quagga-0.99.15-7.el6_3.2.x86_64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/quagga-0.99.15-7.el6_3.2.src.rpm i386: quagga-contrib-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm quagga-devel-0.99.15-7.el6_3.2.i686.rpm ppc64: quagga-contrib-0.99.15-7.el6_3.2.ppc64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.ppc.rpm quagga-debuginfo-0.99.15-7.el6_3.2.ppc64.rpm quagga-devel-0.99.15-7.el6_3.2.ppc.rpm quagga-devel-0.99.15-7.el6_3.2.ppc64.rpm s390x: quagga-contrib-0.99.15-7.el6_3.2.s390x.rpm quagga-debuginfo-0.99.15-7.el6_3.2.s390.rpm quagga-debuginfo-0.99.15-7.el6_3.2.s390x.rpm quagga-devel-0.99.15-7.el6_3.2.s390.rpm quagga-devel-0.99.15-7.el6_3.2.s390x.rpm x86_64: quagga-contrib-0.99.15-7.el6_3.2.x86_64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.x86_64.rpm quagga-devel-0.99.15-7.el6_3.2.i686.rpm quagga-devel-0.99.15-7.el6_3.2.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/quagga-0.99.15-7.el6_3.2.src.rpm i386: quagga-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm x86_64: quagga-0.99.15-7.el6_3.2.x86_64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/quagga-0.99.15-7.el6_3.2.src.rpm i386: quagga-contrib-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm quagga-devel-0.99.15-7.el6_3.2.i686.rpm x86_64: quagga-contrib-0.99.15-7.el6_3.2.x86_64.rpm quagga-debuginfo-0.99.15-7.el6_3.2.i686.rpm quagga-debuginfo-0.99.15-7.el6_3.2.x86_64.rpm quagga-devel-0.99.15-7.el6_3.2.i686.rpm quagga-devel-0.99.15-7.el6_3.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2011-3323.html https://www.redhat.com/security/data/cve/CVE-2011-3324.html https://www.redhat.com/security/data/cve/CVE-2011-3325.html https://www.redhat.com/security/data/cve/CVE-2011-3326.html https://www.redhat.com/security/data/cve/CVE-2011-3327.html https://www.redhat.com/security/data/cve/CVE-2012-0249.html https://www.redhat.com/security/data/cve/CVE-2012-0250.html https://www.redhat.com/security/data/cve/CVE-2012-0255.html https://www.redhat.com/security/data/cve/CVE-2012-1820.html https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFQUOxMXlSAg2UNWIIRAspnAKDCd5umtQIWFZYD8vyRPpCkAlgiwwCglw+g P4VSjxs4xRnVCtT/IOkBkKQ= =VtuC -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce. This security update upgrades the quagga package to the most recent upstream release. This release includes other corrections, such as hardening against unknown BGP path attributes. For the stable distribution (squeeze), these problems have been fixed in version 0.99.20.1-0+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 0.99.20.1-1

Trust: 3.15

sources: NVD: CVE-2012-0249 // CERT/CC: VU#551715 // JVNDB: JVNDB-2012-002004 // BID: 52531 // PACKETSTORM: 112732 // PACKETSTORM: 112206 // PACKETSTORM: 116468 // PACKETSTORM: 123565 // PACKETSTORM: 116469 // PACKETSTORM: 112209

AFFECTED PRODUCTS

vendor:quaggamodel:quaggascope:eqversion:0.96.5

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.5

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.98.0

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.3

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.96.4

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.98.1

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.4

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.1

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.0

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.97.2

Trust: 1.6

vendor:quaggamodel:quaggascope:eqversion:0.99.8

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.10

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.19

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.1

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.98.4

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.18

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.96.3

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.14

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.2

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.98.3

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.5

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.16

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.96.1

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.95

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.15

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.98.5

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.12

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.96

Trust: 1.0

vendor:quaggamodel:quaggascope:lteversion:0.99.20

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.11

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.96.2

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.3

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.17

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.7

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.98.6

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.98.2

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.9

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.4

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.13

Trust: 1.0

vendor:quaggamodel:quaggascope:eqversion:0.99.6

Trust: 1.0

vendor:quaggamodel: - scope: - version: -

Trust: 0.8

vendor:quaggamodel:quaggascope:ltversion:0.99.20.1

Trust: 0.8

vendor:internet initiativemodel:seil/b1scope:eqversion:1.00 to 3.70

Trust: 0.8

vendor:internet initiativemodel:seil/neu 2fe plusscope:eqversion:1.00 to 2.13

Trust: 0.8

vendor:internet initiativemodel:seil/turboscope:eqversion:1.00 to 2.13

Trust: 0.8

vendor:internet initiativemodel:seil/x1scope:eqversion:1.00 to 3.70

Trust: 0.8

vendor:internet initiativemodel:seil/x2scope:eqversion:1.00 to 3.70

Trust: 0.8

vendor:internet initiativemodel:seil/x86scope:eqversion:1.70 to 2.31

Trust: 0.8

vendor:ubuntumodel:linux lts i386scope:eqversion:12.04

Trust: 0.3

vendor:ubuntumodel:linux lts amd64scope:eqversion:12.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:11.10

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:11.10

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:11.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:11.04

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:11.04

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:11.04

Trust: 0.3

vendor:ubuntumodel:linux sparcscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:10.04

Trust: 0.3

vendor:redhatmodel:enterprise linux workstationscope:eqversion:6

Trust: 0.3

vendor:redhatmodel:enterprise linux serverscope:eqversion:6

Trust: 0.3

vendor:redhatmodel:enterprise linux desktop workstation clientscope:eqversion:5

Trust: 0.3

vendor:redhatmodel:enterprise linux desktop clientscope:eqversion:5

Trust: 0.3

vendor:redhatmodel:enterprise linux serverscope:eqversion:5

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.19

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.17

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.16

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.15

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.11

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.9

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.8

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.7

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.6

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.5

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.4

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.3

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.2

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.99.1

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.98.6

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.98.5

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.98.3

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.97.3

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.96.4

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.96.3

Trust: 0.3

vendor:quaggamodel:routing software suitescope:eqversion:0.96.2

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:6.2

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:6

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:5

Trust: 0.3

vendor:mcafeemodel:firewall enterprise 8.2.1p03scope: - version: -

Trust: 0.3

vendor:mcafeemodel:firewall enterprise 7.0.1.03h04scope: - version: -

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:6.0

Trust: 0.3

vendor:quaggamodel:routing software suitescope:neversion:0.99.20.1

Trust: 0.3

vendor:mcafeemodel:firewall enterprise 8.2.1p04scope:neversion: -

Trust: 0.3

vendor:mcafeemodel:firewall enterprise 7.0.1.05.h05scope:neversion: -

Trust: 0.3

sources: CERT/CC: VU#551715 // BID: 52531 // JVNDB: JVNDB-2012-002004 // CNNVD: CNNVD-201204-066 // NVD: CVE-2012-0249

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-0249
value: LOW

Trust: 1.0

CARNEGIE MELLON: VU#551715
value: MEDIUM

Trust: 0.8

NVD: CVE-2012-0249
value: LOW

Trust: 0.8

CNNVD: CNNVD-201204-066
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2012-0249
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CARNEGIE MELLON: VU#551715
severity: MEDIUM
baseScore: 6.1
vectorString: NONE
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

sources: CERT/CC: VU#551715 // JVNDB: JVNDB-2012-002004 // CNNVD: CNNVD-201204-066 // NVD: CVE-2012-0249

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2012-002004 // NVD: CVE-2012-0249

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201204-066

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201204-066

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-002004

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#551715

PATCH

title:FEDORA-2012-5436url:http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.html

Trust: 0.8

title:FEDORA-2012-5411url:http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.html

Trust: 0.8

title:FEDORA-2012-5352url:http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.html

Trust: 0.8

title:Bug 705url:https://bugzilla.quagga.net/show_bug.cgi?id=705

Trust: 0.8

title:Quagga Routing Suiteurl:http://www.nongnu.org/quagga/

Trust: 0.8

title:RHSA-2012:1258url:http://rhn.redhat.com/errata/RHSA-2012-1258.html

Trust: 0.8

title:RHSA-2012:1259url:http://rhn.redhat.com/errata/RHSA-2012-1259.html

Trust: 0.8

title:Multiple Vulnerabilities in Quaggaurl:http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_quagga

Trust: 0.8

title:偽装されたOSPFv2パケットに対する受信処理の脆弱性url:http://www.seil.jp/support/security/a01221.html

Trust: 0.8

sources: JVNDB: JVNDB-2012-002004

EXTERNAL IDS

db:CERT/CCid:VU#551715

Trust: 3.2

db:NVDid:CVE-2012-0249

Trust: 3.2

db:SECUNIAid:48949

Trust: 1.1

db:JVNDBid:JVNDB-2012-002004

Trust: 0.8

db:NSFOCUSid:20680

Trust: 0.6

db:NSFOCUSid:20685

Trust: 0.6

db:CNNVDid:CNNVD-201204-066

Trust: 0.6

db:BIDid:52531

Trust: 0.3

db:PACKETSTORMid:112732

Trust: 0.1

db:PACKETSTORMid:112206

Trust: 0.1

db:PACKETSTORMid:116468

Trust: 0.1

db:PACKETSTORMid:123565

Trust: 0.1

db:PACKETSTORMid:116469

Trust: 0.1

db:PACKETSTORMid:112209

Trust: 0.1

sources: CERT/CC: VU#551715 // BID: 52531 // JVNDB: JVNDB-2012-002004 // PACKETSTORM: 112732 // PACKETSTORM: 112206 // PACKETSTORM: 116468 // PACKETSTORM: 123565 // PACKETSTORM: 116469 // PACKETSTORM: 112209 // CNNVD: CNNVD-201204-066 // NVD: CVE-2012-0249

REFERENCES

url:https://bugzilla.quagga.net/show_bug.cgi?id=705

Trust: 2.4

url:http://www.kb.cert.org/vuls/id/551715

Trust: 2.4

url:http://rhn.redhat.com/errata/rhsa-2012-1258.html

Trust: 1.4

url:http://rhn.redhat.com/errata/rhsa-2012-1259.html

Trust: 1.4

url:http://www.nongnu.org/quagga/

Trust: 1.1

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078794.html

Trust: 1.0

url:http://www.debian.org/security/2012/dsa-2459

Trust: 1.0

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078910.html

Trust: 1.0

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078926.html

Trust: 1.0

url:http://secunia.com/advisories/48949

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-0249

Trust: 0.8

url:http://jvn.jp/cert/jvnvu551715/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-0249

Trust: 0.8

url:http://www.nsfocus.net/vulndb/20685

Trust: 0.6

url:http://www.nsfocus.net/vulndb/20680

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2012-0250

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2012-0249

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2012-0255

Trust: 0.4

url:https://kc.mcafee.com/corporate/index?page=content&id=kb76173

Trust: 0.3

url:http://savannah.nongnu.org/forum/forum.php?forum_id=7151

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-3323.html

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3325.html

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3323

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3324.html

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3326

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3325

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3324

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3327

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2012-0249.html

Trust: 0.2

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2012-0250.html

Trust: 0.2

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3326.html

Trust: 0.2

url:https://access.redhat.com/security/team/key/#package

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3327.html

Trust: 0.2

url:http://bugzilla.redhat.com/):

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-1820

Trust: 0.2

url:https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.10.04.2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.11.04.2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.11.10.2

Trust: 0.1

url:http://www.ubuntu.com/usn/usn-1441-1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.12.04.2

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=48949

Trust: 0.1

url:http://lists.debian.org/debian-security-announce/2012/msg00092.html

Trust: 0.1

url:http://secunia.com/psi_30_beta_launch

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/48949/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/48949/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2010-1674.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1674

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-1820

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201310-08.xml

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2236

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-2236

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0249

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0250

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0255

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0255.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-1820.html

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

sources: CERT/CC: VU#551715 // BID: 52531 // JVNDB: JVNDB-2012-002004 // PACKETSTORM: 112732 // PACKETSTORM: 112206 // PACKETSTORM: 116468 // PACKETSTORM: 123565 // PACKETSTORM: 116469 // PACKETSTORM: 112209 // CNNVD: CNNVD-201204-066 // NVD: CVE-2012-0249

CREDITS

MU Dynamics.

Trust: 0.3

sources: BID: 52531

SOURCES

db:CERT/CCid:VU#551715
db:BIDid:52531
db:JVNDBid:JVNDB-2012-002004
db:PACKETSTORMid:112732
db:PACKETSTORMid:112206
db:PACKETSTORMid:116468
db:PACKETSTORMid:123565
db:PACKETSTORMid:116469
db:PACKETSTORMid:112209
db:CNNVDid:CNNVD-201204-066
db:NVDid:CVE-2012-0249

LAST UPDATE DATE

2024-11-23T21:19:15.188000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#551715date:2012-03-28T00:00:00
db:BIDid:52531date:2015-04-13T21:16:00
db:JVNDBid:JVNDB-2012-002004date:2012-11-13T00:00:00
db:CNNVDid:CNNVD-201204-066date:2012-04-10T00:00:00
db:NVDid:CVE-2012-0249date:2024-11-21T01:34:39.737

SOURCES RELEASE DATE

db:CERT/CCid:VU#551715date:2012-03-23T00:00:00
db:BIDid:52531date:2012-03-16T00:00:00
db:JVNDBid:JVNDB-2012-002004date:2012-04-09T00:00:00
db:PACKETSTORMid:112732date:2012-05-15T21:57:44
db:PACKETSTORMid:112206date:2012-04-26T01:55:38
db:PACKETSTORMid:116468date:2012-09-12T23:06:05
db:PACKETSTORMid:123565date:2013-10-10T12:14:00
db:PACKETSTORMid:116469date:2012-09-12T23:06:22
db:PACKETSTORMid:112209date:2012-04-26T21:55:46
db:CNNVDid:CNNVD-201204-066date:2010-04-06T00:00:00
db:NVDid:CVE-2012-0249date:2012-04-05T13:25:30.553