Unrated severityNVD Advisory· Published Apr 5, 2012· Updated Apr 29, 2026
CVE-2012-0250
CVE-2012-0250
Description
Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.
Affected products
20cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.12:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.99.20
- cpe:2.3:a:quagga:quagga:0.99.1:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.2:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.4:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.5:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.6:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.7:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.8:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.9:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.10:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.13:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.14:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.15:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.16:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.17:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.18:*:*:*:*:*:*:*
- cpe:2.3:a:quagga:quagga:0.99.19:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.kb.cert.org/vuls/id/551715nvdUS Government Resource
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1258.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1259.htmlnvd
- secunia.com/advisories/48949nvd
- www.debian.org/security/2012/dsa-2459nvd
News mentions
0No linked articles in our index yet.