Vulnerability Description
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bird Project | Bird | < 1.6.4 |
Related Weaknesses (CWE)
References
- http://bird.network.czThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900967Issue TrackingThird Party Advisory
- https://gitlab.labs.nic.cz/labs/bird/blob/v1.6.4/NEWS#L11Issue TrackingThird Party Advisory
- https://gitlab.labs.nic.cz/labs/bird/commit/e8bc64e308586b6502090da2775af84cd760Issue TrackingPatchThird Party Advisory
- http://bird.network.czThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900967Issue TrackingThird Party Advisory
- https://gitlab.labs.nic.cz/labs/bird/blob/v1.6.4/NEWS#L11Issue TrackingThird Party Advisory
- https://gitlab.labs.nic.cz/labs/bird/commit/e8bc64e308586b6502090da2775af84cd760Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2018-12066?
CVE-2018-12066 is a vulnerability with a CVSS score of 5.5 (MEDIUM). BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
How severe is CVE-2018-12066?
CVE-2018-12066 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12066?
Check the references section above for vendor advisories and patch information. Affected products include: Bird Project Bird.