CVE-2012-0250

low
Published 2012-04-05 · Modified 2026-04-29
CVSS v3
CVSS v2
3.3
VIR risk
3.3

Description

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
quaggaquagga{"endIncluding":"0.99.20"}
quaggaquagga0.99.1
quaggaquagga0.99.2
quaggaquagga0.99.3
quaggaquagga0.99.4
quaggaquagga0.99.5
quaggaquagga0.99.6
quaggaquagga0.99.7
quaggaquagga0.99.8
quaggaquagga0.99.9
quaggaquagga0.99.10
quaggaquagga0.99.11
quaggaquagga0.99.12
quaggaquagga0.99.13
quaggaquagga0.99.14
quaggaquagga0.99.15
quaggaquagga0.99.16
quaggaquagga0.99.17
quaggaquagga0.99.18
quaggaquagga0.99.19

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.