CVE-2012-1820
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2012
Last modified:
11/04/2025
Description
The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.
Impact
Base Score 2.0
2.90
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:* | 0.99.20.1 (including) | |
| cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://rhn.redhat.com/errata/RHSA-2012-1259.html
- http://secunia.com/advisories/50941
- http://www.debian.org/security/2012/dsa-2497
- http://www.kb.cert.org/vuls/id/962587
- http://www.securityfocus.com/bid/53775
- http://www.ubuntu.com/usn/USN-1605-1
- http://rhn.redhat.com/errata/RHSA-2012-1259.html
- http://secunia.com/advisories/50941
- http://www.debian.org/security/2012/dsa-2497
- http://www.kb.cert.org/vuls/id/962587
- http://www.securityfocus.com/bid/53775
- http://www.ubuntu.com/usn/USN-1605-1



