CVE-2016-1245

critical
Published 2017-02-22 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.gossamer-threads.com/lists/quagga/users/31952

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-1245.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian8.0affected

Application impact

VendorProductVersionsFixed
quaggaquagga{"endIncluding":"1.0.20160315"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.