VYPR
Unrated severityNVD Advisory· Published Sep 10, 2010· Updated Apr 29, 2026

CVE-2010-2948

CVE-2010-2948

Description

Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.

Affected products

36
  • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*+ 35 more
    • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.99.16
    • cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.6:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.10:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.12:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.13:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.14:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.15:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.6:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.7:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.8:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.