CVE-2011-3324

Quagga < 0.99.19 - Denial of Service via OSPFv3 LSA Header Parsing

Title source: llm
STIX 2.1

Description

The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via trailing zero values in the Link State Advertisement (LSA) header list of an IPv6 Database Description message.

References (15)

Core 15
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1259.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1258.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/668534
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2316
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46139
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201202-02.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46274
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48106

Scores

EPSS 0.0467
EPSS Percentile 90.7%

Details

CWE
CWE-399
Status published
Products (38)
quagga/quagga 0.95
quagga/quagga 0.96
quagga/quagga 0.96.1
quagga/quagga 0.96.2
quagga/quagga 0.96.3
quagga/quagga 0.96.4
quagga/quagga 0.96.5
quagga/quagga 0.97.0
quagga/quagga 0.97.1
quagga/quagga 0.97.2
... and 28 more
Published Oct 10, 2011
Tracked Since Feb 18, 2026