// For flags

CVE-2010-2948

(bgpd): Stack buffer overflow by processing certain Route-Refresh messages

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.

Desbordamiento de búfer basado en pila en la función bgp_route_refresh_receive en bgp_packet.c en bgpd en Quagga anterior a v0.99.17, permite a usuarios remotos autenticados provocar una denegación de servicio (caída del demonio) o posiblemente ejecutar código a través de un registro Outbound Route Filtering (ORF) formado de forma errónea en un mensaje BGP ROUTE-REFRESH (RR).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-08-04 CVE Reserved
  • 2010-09-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-121: Stack-based Buffer Overflow
CAPEC
References (24)
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
<= 0.99.16
Search vendor "Quagga" for product "Quagga" and version " <= 0.99.16"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.95
Search vendor "Quagga" for product "Quagga" and version "0.95"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96
Search vendor "Quagga" for product "Quagga" and version "0.96"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.1
Search vendor "Quagga" for product "Quagga" and version "0.96.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.2
Search vendor "Quagga" for product "Quagga" and version "0.96.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.3
Search vendor "Quagga" for product "Quagga" and version "0.96.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.4
Search vendor "Quagga" for product "Quagga" and version "0.96.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.5
Search vendor "Quagga" for product "Quagga" and version "0.96.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.0
Search vendor "Quagga" for product "Quagga" and version "0.97.0"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.1
Search vendor "Quagga" for product "Quagga" and version "0.97.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.2
Search vendor "Quagga" for product "Quagga" and version "0.97.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.3
Search vendor "Quagga" for product "Quagga" and version "0.97.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.4
Search vendor "Quagga" for product "Quagga" and version "0.97.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.5
Search vendor "Quagga" for product "Quagga" and version "0.97.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.0
Search vendor "Quagga" for product "Quagga" and version "0.98.0"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.1
Search vendor "Quagga" for product "Quagga" and version "0.98.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.2
Search vendor "Quagga" for product "Quagga" and version "0.98.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.3
Search vendor "Quagga" for product "Quagga" and version "0.98.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.4
Search vendor "Quagga" for product "Quagga" and version "0.98.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.5
Search vendor "Quagga" for product "Quagga" and version "0.98.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.6
Search vendor "Quagga" for product "Quagga" and version "0.98.6"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.1
Search vendor "Quagga" for product "Quagga" and version "0.99.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.2
Search vendor "Quagga" for product "Quagga" and version "0.99.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.3
Search vendor "Quagga" for product "Quagga" and version "0.99.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.4
Search vendor "Quagga" for product "Quagga" and version "0.99.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.5
Search vendor "Quagga" for product "Quagga" and version "0.99.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.6
Search vendor "Quagga" for product "Quagga" and version "0.99.6"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.7
Search vendor "Quagga" for product "Quagga" and version "0.99.7"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.8
Search vendor "Quagga" for product "Quagga" and version "0.99.8"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.9
Search vendor "Quagga" for product "Quagga" and version "0.99.9"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.10
Search vendor "Quagga" for product "Quagga" and version "0.99.10"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.11
Search vendor "Quagga" for product "Quagga" and version "0.99.11"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.12
Search vendor "Quagga" for product "Quagga" and version "0.99.12"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.13
Search vendor "Quagga" for product "Quagga" and version "0.99.13"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.14
Search vendor "Quagga" for product "Quagga" and version "0.99.14"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.15
Search vendor "Quagga" for product "Quagga" and version "0.99.15"
-
Affected