VYPR
Unrated severityNVD Advisory· Published Apr 12, 2007· Updated Apr 23, 2026

CVE-2007-1995

CVE-2007-1995

Description

bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.

Affected products

20
  • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.98.6
    • cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

26

News mentions

0

No linked articles in our index yet.