VYPR
Unrated severityNVD Advisory· Published Oct 24, 2013· Updated Apr 29, 2026

CVE-2013-2236

CVE-2013-2236

Description

Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.

Affected products

2
  • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.99.22.1
    • cpe:2.3:a:quagga:quagga:0.99.22:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.