CVE-2013-6051
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/12/2013
Last modified:
11/04/2025
Description
The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:quagga:quagga:0.99.21:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=730513
- http://git.savannah.gnu.org/gitweb/?p=quagga.git%3Ba%3Dcommitdiff%3Bh%3D8794e8d229dc9fe29ea31424883433d4880ef408
- http://www.debian.org/security/2013/dsa-2803
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=730513
- http://git.savannah.gnu.org/gitweb/?p=quagga.git%3Ba%3Dcommitdiff%3Bh%3D8794e8d229dc9fe29ea31424883433d4880ef408
- http://www.debian.org/security/2013/dsa-2803



