Oval Definition:oval:org.mitre.oval:tst:34117
Comment:quagga-devel is earlier than 0:0.98.3-2.4.0.1.el4
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14340
State:oval:org.mitre.oval:ste:10249
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:11048
V
bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.
2013-04-29
BACK