// For flags

CVE-2012-0249

(ospfd): Assertion failure due improper length check for a received LS-Update OSPF packet

Severity Score

3.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.

Desbordamiento de búfer en la función ospf_ls_upd_list_lsa en ospf_packet.c en la implementación de OSPFv2 en ospfd en Quagga antes v0.99.20.1 permite a atacantes remotos causar una denegación de servicio (error de aserción y salida del demonio) a través de un paquete de actualización de estado de enlace (también conocido como LS Update) que es más pequeño de lo que indica la longitud especificada en su cabecera.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-12-21 CVE Reserved
  • 2012-04-05 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-10-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
<= 0.99.20
Search vendor "Quagga" for product "Quagga" and version " <= 0.99.20"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.95
Search vendor "Quagga" for product "Quagga" and version "0.95"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96
Search vendor "Quagga" for product "Quagga" and version "0.96"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.1
Search vendor "Quagga" for product "Quagga" and version "0.96.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.2
Search vendor "Quagga" for product "Quagga" and version "0.96.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.3
Search vendor "Quagga" for product "Quagga" and version "0.96.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.4
Search vendor "Quagga" for product "Quagga" and version "0.96.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.96.5
Search vendor "Quagga" for product "Quagga" and version "0.96.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.0
Search vendor "Quagga" for product "Quagga" and version "0.97.0"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.1
Search vendor "Quagga" for product "Quagga" and version "0.97.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.2
Search vendor "Quagga" for product "Quagga" and version "0.97.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.3
Search vendor "Quagga" for product "Quagga" and version "0.97.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.4
Search vendor "Quagga" for product "Quagga" and version "0.97.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.97.5
Search vendor "Quagga" for product "Quagga" and version "0.97.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.0
Search vendor "Quagga" for product "Quagga" and version "0.98.0"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.1
Search vendor "Quagga" for product "Quagga" and version "0.98.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.2
Search vendor "Quagga" for product "Quagga" and version "0.98.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.3
Search vendor "Quagga" for product "Quagga" and version "0.98.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.4
Search vendor "Quagga" for product "Quagga" and version "0.98.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.5
Search vendor "Quagga" for product "Quagga" and version "0.98.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.98.6
Search vendor "Quagga" for product "Quagga" and version "0.98.6"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.1
Search vendor "Quagga" for product "Quagga" and version "0.99.1"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.2
Search vendor "Quagga" for product "Quagga" and version "0.99.2"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.3
Search vendor "Quagga" for product "Quagga" and version "0.99.3"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.4
Search vendor "Quagga" for product "Quagga" and version "0.99.4"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.5
Search vendor "Quagga" for product "Quagga" and version "0.99.5"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.6
Search vendor "Quagga" for product "Quagga" and version "0.99.6"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.7
Search vendor "Quagga" for product "Quagga" and version "0.99.7"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.8
Search vendor "Quagga" for product "Quagga" and version "0.99.8"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.9
Search vendor "Quagga" for product "Quagga" and version "0.99.9"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.10
Search vendor "Quagga" for product "Quagga" and version "0.99.10"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.11
Search vendor "Quagga" for product "Quagga" and version "0.99.11"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.12
Search vendor "Quagga" for product "Quagga" and version "0.99.12"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.13
Search vendor "Quagga" for product "Quagga" and version "0.99.13"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.14
Search vendor "Quagga" for product "Quagga" and version "0.99.14"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.15
Search vendor "Quagga" for product "Quagga" and version "0.99.15"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.16
Search vendor "Quagga" for product "Quagga" and version "0.99.16"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.17
Search vendor "Quagga" for product "Quagga" and version "0.99.17"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.18
Search vendor "Quagga" for product "Quagga" and version "0.99.18"
-
Affected
Quagga
Search vendor "Quagga"
Quagga
Search vendor "Quagga" for product "Quagga"
0.99.19
Search vendor "Quagga" for product "Quagga" and version "0.99.19"
-
Affected