ID | CVE-2016-2342 | ||||||
Sažetak | The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted packet. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:H/Au:N/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 05-01-2018 - 02:30 | ||||||
Objavljeno | 17-03-2016 - 14:59 |