CVE-2012-0249

low
Published 2012-04-05 · Modified 2026-04-29
CVSS v3
CVSS v2
3.3
VIR risk
3.3

Description

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — https://bugzilla.quagga.net/show_bug.cgi?id=705

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://www.kb.cert.org/vuls/id/551715

Application impact

VendorProductVersionsFixed
quaggaquagga{"endIncluding":"0.99.20"}
quaggaquagga0.95
quaggaquagga0.96
quaggaquagga0.96.1
quaggaquagga0.96.2
quaggaquagga0.96.3
quaggaquagga0.96.4
quaggaquagga0.96.5
quaggaquagga0.97.0
quaggaquagga0.97.1
quaggaquagga0.97.2
quaggaquagga0.97.3
quaggaquagga0.97.4
quaggaquagga0.97.5
quaggaquagga0.98.0
quaggaquagga0.98.1
quaggaquagga0.98.2
quaggaquagga0.98.3
quaggaquagga0.98.4
quaggaquagga0.98.5
quaggaquagga0.98.6
quaggaquagga0.99.1
quaggaquagga0.99.2
quaggaquagga0.99.3
quaggaquagga0.99.4
quaggaquagga0.99.5
quaggaquagga0.99.6
quaggaquagga0.99.7
quaggaquagga0.99.8
quaggaquagga0.99.9
quaggaquagga0.99.10
quaggaquagga0.99.11
quaggaquagga0.99.12
quaggaquagga0.99.13
quaggaquagga0.99.14
quaggaquagga0.99.15
quaggaquagga0.99.16
quaggaquagga0.99.17
quaggaquagga0.99.18
quaggaquagga0.99.19

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.