Unrated severityNVD Advisory· Published Apr 5, 2012· Updated Apr 29, 2026
CVE-2012-0249
CVE-2012-0249
Description
Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.
Affected products
40cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*+ 39 more
- cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.6:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.1:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.2:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.4:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.5:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.6:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.7:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.99.20
- cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.8:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.9:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.10:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.12:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.13:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.14:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.15:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.16:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.17:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.18:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.19:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.kb.cert.org/vuls/id/551715nvdPatchUS Government Resource
- bugzilla.quagga.net/show_bug.cginvdExploitPatch
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1258.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1259.htmlnvd
- secunia.com/advisories/48949nvd
- www.debian.org/security/2012/dsa-2459nvd
News mentions
0No linked articles in our index yet.