Vulnerability Description
The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quagga | Quagga | 0.99.21 |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=730513
- http://git.savannah.gnu.org/gitweb/?p=quagga.git%3Ba=commitdiff%3Bh=8794e8d229dc
- http://www.debian.org/security/2013/dsa-2803
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=730513
- http://git.savannah.gnu.org/gitweb/?p=quagga.git%3Ba=commitdiff%3Bh=8794e8d229dc
- http://www.debian.org/security/2013/dsa-2803
FAQ
What is CVE-2013-6051?
CVE-2013-6051 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP...
How severe is CVE-2013-6051?
CVE-2013-6051 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6051?
Check the references section above for vendor advisories and patch information. Affected products include: Quagga Quagga.