CVE-2018-5378 - CERT CVE
ID CVE-2018-5378
Sažetak The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.
Reference
CVSS
Base: 4.9
Impact: 4.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE PARTIAL
CVSS vektor AV:N/AC:M/Au:S/C:P/I:N/A:P
Zadnje važnije ažuriranje 09-10-2019 - 23:41
Objavljeno 19-02-2018 - 13:29