CVE-2011-3327

Publication date 10 October 2011

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

Status

Package Ubuntu Release Status
quagga 11.10 oneiric
Fixed 0.99.18-2ubuntu0.1
11.04 natty
Fixed 0.99.17-4ubuntu1.1
10.10 maverick
Fixed 0.99.17-1ubuntu0.2
10.04 LTS lucid
Fixed 0.99.15-1ubuntu0.3
8.04 LTS hardy Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1261-1
    • Quagga vulnerabilities
    • 14 November 2011

Other references