CVE-2016-1245

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
22/02/2017
Last modified:
20/04/2025

Description

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:* 1.0.20160315 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*