CVE-2010-2949 PUBLISHED CVSS 5 MEDIUM

bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a BGP UPDATE message.

EPSS 4.64% · 89.2th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
4.64%
89.2th percentile

Affected Products

VendorProductVersions
quaggaquagga0.99.15, 0, 0.95
n/an/an/a

Timeline

References

…and 4 more

Open in Interactive Console →