Vigil@nce - Quagga Routing Suite: two vulnerabilities
August 2010 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/
SYNTHESIS OF THE VULNERABILITY
Two vulnerabilities in Quagga Routing Suite can be used by an attacker to create a denial of service or possibly to execute code.
Severity: 2/4
Creation date: 24/08/2010
DESCRIPTION OF THE VULNERABILITY
Two vulnerabilities were announced in BGP.
An attacker can send a malicious BGP "Outbound Route Filtering" message in order to generate a stack overflow in BGP daemon. [severity:2/4; 626783, CVE-2010-2948]
An attacker can send a malicious BGP "update AS path" in order to generate a denial of service of BPG daemon. [severity:2/4; 626795, CVE-2010-2949]
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN





News





