VDB
CVE-2006-2224
CVE-2006-2224
PUBLISHED
CVSS 5 MEDIUM
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
EPSS 10.36% · 95.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
10.36%
95.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| quagga | quagga_routing_software_suite | 0, 0.95, 0.96.2 |
Timeline
- May 3, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- Sep 28, 2023 EPSS Score
- Nov 15, 2023 EPSS Score
- Jan 9, 2024 EPSS Score
- Mar 25, 2024 EPSS Score
- Aug 24, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Mar 22, 2025 EPSS Score
- Mar 23, 2025 EPSS Score
References
- 20138 third-party-advisory
- RHSA-2006:0533 vendor-advisory
- 20221 third-party-advisory
- USN-284-1 vendor-advisory
- 20060503 Re: Quagga RIPD unauthenticated route injection mailing-list
- 25225 vdb
- 1016204 vdb
- GLSA-200605-15 vendor-advisory
- 20060503 Quagga RIPD unauthenticated route injection mailing-list
- 20420 third-party-advisory
- http://bugzilla.quagga.net/show_bug.cgi?id=262 patch
- http://secunia.com/advisories/20421 advisory
- http://www.debian.org/security/2006/dsa-1059 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26251 technical
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc technical
- http://secunia.com/advisories/20137 advisory
- http://secunia.com/advisories/20782 advisory
- http://secunia.com/advisories/21159 advisory
- http://www.novell.com/linux/security/advisories/2006_17_sr.html technical
- http://www.securityfocus.com/bid/17808 exploit
…and 5 more