ZeroHour

CVE-2018-5379

CVSS 3.0
9.8 critical
EPSS
38%p98
Published
()
Modified
Description

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

Vendors
quaggadebiancanonicalredhatsiemens
Products
quagga, debian linux, ubuntu linux, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, ruggedcom rox ii firmware
Weakness
CWE-415
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.