CVE-2012-1820

low
Published 2012-06-13 · Modified 2026-04-29
CVSS v3
CVSS v2
2.9
VIR risk
2.9

Description

The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
quaggaquagga{"endIncluding":"0.99.20.1"}
quaggaquagga0.95
quaggaquagga0.96
quaggaquagga0.96.1
quaggaquagga0.96.2
quaggaquagga0.96.3
quaggaquagga0.96.4
quaggaquagga0.96.5
quaggaquagga0.97.0
quaggaquagga0.97.1
quaggaquagga0.97.2
quaggaquagga0.97.3
quaggaquagga0.97.4
quaggaquagga0.97.5
quaggaquagga0.98.0
quaggaquagga0.98.1
quaggaquagga0.98.2
quaggaquagga0.98.3
quaggaquagga0.98.4
quaggaquagga0.98.5
quaggaquagga0.98.6
quaggaquagga0.99.1
quaggaquagga0.99.2
quaggaquagga0.99.3
quaggaquagga0.99.4
quaggaquagga0.99.5
quaggaquagga0.99.6
quaggaquagga0.99.7
quaggaquagga0.99.8
quaggaquagga0.99.9
quaggaquagga0.99.10
quaggaquagga0.99.11
quaggaquagga0.99.12
quaggaquagga0.99.13
quaggaquagga0.99.14
quaggaquagga0.99.15
quaggaquagga0.99.16
quaggaquagga0.99.17
quaggaquagga0.99.18
quaggaquagga0.99.19
quaggaquagga0.99.20

References

Verify integrity in audit chain (admin only). AS-IS.