Oval Definition:oval:com.ubuntu.precise:def:20162342000
Revision Date:2016-03-17Version:1
Title:CVE-2016-2342 on Ubuntu 12.04 LTS (precise) - high.
Description:The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted packet.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-2342
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'quagga' package in precise was vulnerable but has been fixed (note: '0.99.20.1-0ubuntu0.12.04.4').
  • BACK