Vulnerability Name:

CVE-2006-2224 (CCN-26251)

Assigned:2006-05-03
Published:2006-05-03
Updated:2018-10-18
Summary:RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: SGI
Type: UNKNOWN
20060602-01-U

Source: CCN
Type: BugTraq Mailing List, Tue May 02 2006 - 22:39:34 CDT
Re: Quagga RIPD unauthenticated route injection

Source: CCN
Type: Full-Disclosure Mailing List, Tue May 02 2006 - 20:36:00 CDT
Quagga RIPD unauthenticated route injection

Source: CCN
Type: Quagga Bugzilla Bug 262
arh200604-2: RIPv1 route injection bypasses authentication

Source: CONFIRM
Type: Patch
http://bugzilla.quagga.net/show_bug.cgi?id=262

Source: MITRE
Type: CNA
CVE-2006-2224

Source: CCN
Type: RHSA-2006-0525
quagga security update

Source: CCN
Type: RHSA-2006-0533
zebra security update

Source: CCN
Type: SA19910
Quagga RIPd RIPv1 Request Handling Security Issue

Source: SECUNIA
Type: Patch, Vendor Advisory
19910

Source: SECUNIA
Type: Vendor Advisory
20137

Source: SECUNIA
Type: Vendor Advisory
20138

Source: SECUNIA
Type: Vendor Advisory
20221

Source: SECUNIA
Type: Vendor Advisory
20420

Source: SECUNIA
Type: Vendor Advisory
20421

Source: SECUNIA
Type: Vendor Advisory
20782

Source: SECUNIA
Type: Vendor Advisory
21159

Source: CCN
Type: SECTRACK ID: 1016204
Quagga Bugs Let Remote Users Obtain or Modify Routing Information and Local Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1016204

Source: CCN
Type: ASA-2006-114
zebra security update (RHSA-2006-0533)

Source: CCN
Type: ASA-2006-115
quagga security update (RHSA-2006-0525)

Source: DEBIAN
Type: UNKNOWN
DSA-1059

Source: DEBIAN
Type: DSA-1059
quagga -- several vulnerabilities

Source: CCN
Type: GLSA-200605-15
Quagga Routing Suite: Multiple vulnerabilities

Source: GENTOO
Type: UNKNOWN
GLSA-200605-15

Source: SUSE
Type: UNKNOWN
SUSE-SR:2006:017

Source: OSVDB
Type: UNKNOWN
25225

Source: CCN
Type: OSVDB ID: 25225
Quagga RIPd RIPv1 RESPONSE Packet Route Injection

Source: CCN
Type: Quagga Web site
Quagga Software Routing Suite

Source: REDHAT
Type: UNKNOWN
RHSA-2006:0525

Source: REDHAT
Type: UNKNOWN
RHSA-2006:0533

Source: BUGTRAQ
Type: UNKNOWN
20060503 Re: Quagga RIPD unauthenticated route injection

Source: BUGTRAQ
Type: UNKNOWN
20060503 Quagga RIPD unauthenticated route injection

Source: BID
Type: Exploit, Patch
17808

Source: CCN
Type: BID-17808
Quagga Information Disclosure and Route Injection Vulnerabilities

Source: CCN
Type: USN-284-1
Quagga vulnerabilities

Source: XF
Type: UNKNOWN
quagga-ripd-ripv1-response-security-bypass(26251)

Source: XF
Type: UNKNOWN
quagga-ripd-ripv1-response-security-bypass(26251)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10775

Source: UBUNTU
Type: UNKNOWN
USN-284-1

Source: SUSE
Type: SUSE-SR:2006:017
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:quagga:quagga_routing_software_suite:0.95:*:*:*:*:*:*:*
  • OR cpe:/a:quagga:quagga_routing_software_suite:0.96.2:*:*:*:*:*:*:*
  • OR cpe:/a:quagga:quagga_routing_software_suite:0.96.3:*:*:*:*:*:*:*
  • OR cpe:/a:quagga:quagga_routing_software_suite:0.98.5:*:*:*:*:*:*:*
  • OR cpe:/a:quagga:quagga_routing_software_suite:*:*:*:*:*:*:*:* (Version <= 0.99.3)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:quagga:quagga:0.98.5:*:*:*:*:*:*:*
  • OR cpe:/a:quagga:quagga:0.99.3:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:10775
    V
    RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
    2013-04-29
    oval:org.opensuse.security:def:20062224
    V
    CVE-2006-2224
    2012-08-30
    oval:com.redhat.rhsa:def:20060525
    P
    RHSA-2006:0525: quagga security update (Moderate)
    2006-06-01
    oval:org.debian:def:1059
    V
    several vulnerabilities
    2006-05-19
    BACK
    quagga quagga routing software suite 0.95
    quagga quagga routing software suite 0.96.2
    quagga quagga routing software suite 0.96.3
    quagga quagga routing software suite 0.98.5
    quagga quagga routing software suite *
    quagga quagga 0.98.5
    quagga quagga 0.99.3
    gentoo linux *
    redhat enterprise linux 2.1
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    debian debian linux 3.1
    redhat linux advanced workstation 2.1