Bug 1542972 (CVE-2018-5378) - CVE-2018-5378 quagga: bgpd does not properly bounds check the data sent with a NOTIFY allowing leak of sensitive data or crash
Summary: CVE-2018-5378 quagga: bgpd does not properly bounds check the data sent with ...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-5378
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1546009 1546010
Blocks: 1543001
TreeView+ depends on / blocked
 
Reported: 2018-02-07 13:41 UTC by Adam Mariš
Modified: 2021-03-11 17:08 UTC (History)
7 users (show)

Fixed In Version: quagga 1.2.3
Doc Type: If docs needed, set a value
Doc Text:
An out-of-bounds read vulnerability was discovered in Quagga. A BGP peer could send a specially crafted message which would cause Quagga to read out of bounds, potentially causing a crash or disclosure of up to 64KB process memory to the peer.
Clone Of:
Environment:
Last Closed: 2019-06-08 03:39:24 UTC


Attachments (Terms of Use)
Upstream patch (2.77 KB, patch)
2018-02-07 14:24 UTC, Adam Mariš
no flags Details | Diff

Description Adam Mariš 2018-02-07 13:41:14 UTC
The Quagga BGP daemon, bgpd, does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or it may crash.

Affected versions: 1.1.0, 1.1.1, 1.2.0, 1.2.1, 1.2.2

Comment 1 Adam Mariš 2018-02-07 13:41:17 UTC
Acknowledgments:

Name: the Quagga project

Comment 2 Adam Mariš 2018-02-07 14:24:50 UTC
Created attachment 1392686 [details]
Upstream patch

Comment 3 Doran Moppert 2018-02-13 04:15:39 UTC
External References:

https://www.quagga.net/security/Quagga-2018-0543.txt

Comment 4 Doran Moppert 2018-02-13 04:53:38 UTC
Statement:

This vulnerability affects Quagga versions after 1.1.0. Versions 0.99.x, included with Red Hat Enterprise Linux, are not affected by this issue.

Comment 5 Doran Moppert 2018-02-16 04:37:20 UTC
Created quagga tracking bugs for this issue:

Affects: fedora-all [bug 1546009]


Note You need to log in before you can comment on or make changes to this bug.