CVE-2018-5379

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.

Published : 2018-02-19 13:29 Updated : 2019-10-09 23:41

7.5
CVSS Score More info
Score 7.5 / 10
7.5
Vendor Product Version URI
Quagga Quagga 1.2.2 cpe:/a:quagga:quagga:1.2.2
Debian Debian Linux 8.0 cpe:/o:debian:debian_linux:8.0
Debian Debian Linux 9.0 cpe:/o:debian:debian_linux:9.0
Canonical Ubuntu Linux 14.04 cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~
Canonical Ubuntu Linux 16.04 cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
Canonical Ubuntu Linux 17.10 cpe:/o:canonical:ubuntu_linux:17.10
Debian Debian Linux 7.0 cpe:/o:debian:debian_linux:7.0
Redhat Enterprise Linux Server 7.0 cpe:/o:redhat:enterprise_linux_server:7.0
Redhat Enterprise Linux Server Aus 7.4 cpe:/o:redhat:enterprise_linux_server_aus:7.4
Redhat Enterprise Linux Server Aus 7.6 cpe:/o:redhat:enterprise_linux_server_aus:7.6
Redhat Enterprise Linux Server Eus 7.4 cpe:/o:redhat:enterprise_linux_server_eus:7.4
Redhat Enterprise Linux Server Eus 7.5 cpe:/o:redhat:enterprise_linux_server_eus:7.5
Redhat Enterprise Linux Server Eus 7.6 cpe:/o:redhat:enterprise_linux_server_eus:7.6
Redhat Enterprise Linux Server Tus 7.4 cpe:/o:redhat:enterprise_linux_server_tus:7.4
Redhat Enterprise Linux Server Tus 7.6 cpe:/o:redhat:enterprise_linux_server_tus:7.6
Redhat Enterprise Linux Workstation 7.0 cpe:/o:redhat:enterprise_linux_workstation:7.0
  1. Canonical (1) Search CVE
    1. Ubuntu Linux (3) Search CVE
      1. 14.04
      2. 16.04
      3. 17.10
  2. Quagga (1) Search CVE
    1. Quagga (1) Search CVE
      1. 1.2.2
  3. Redhat (5) Search CVE
    1. Enterprise Linux Server Tus (2) Search CVE
      1. 7.4
      2. 7.6
    2. Enterprise Linux Workstation (1) Search CVE
      1. 7.0
    3. Enterprise Linux Server Eus (3) Search CVE
      1. 7.4
      2. 7.5
      3. 7.6
    4. Enterprise Linux Server Aus (2) Search CVE
      1. 7.4
      2. 7.6
    5. Enterprise Linux Server (1) Search CVE
      1. 7.0
  4. Debian (1) Search CVE
    1. Debian Linux (3) Search CVE
      1. 8.0
      2. 9.0
      3. 7.0

CWE

ID Name Description Links
CWE-415 Double Free The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations. CVE

History of changes

Date Event
2019-04-26 13:08
2019-04-09 13:29
2019-03-05 18:27
2018-10-21 10:29
2018-03-16 01:29
2018-03-14 18:39
2018-03-02 02:29
2018-02-24 02:29
2018-02-20 19:39
2018-02-19 13:29

New CVE