VYPR
Unrated severityNVD Advisory· Published Apr 5, 2012· Updated Apr 29, 2026

CVE-2012-0255

CVE-2012-0255

Description

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).

Affected products

40
  • cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*+ 39 more
    • cpe:2.3:a:quagga:quagga:0.96.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.99.20
    • cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.6:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.7:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.8:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.9:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.10:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.11:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.97.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.0:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.98.6:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.2:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.4:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.19:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.12:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.13:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.14:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.15:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.16:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.17:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.99.18:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.