Short Name |
APP:MISC:QUAGGA-BGP-DOUBLE-FREE |
---|---|
Severity |
Major |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Quagga BGP Daemon bgp_update_receive Double Free |
Release Date |
2018/04/05 |
Update Number |
3053 |
Supported Platforms |
idp-4.0+, isg-3.4.139899+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in the BGP Daemon of Quagga. Successful exploitation could result in the execution of arbitrary code under the security context of the target process. Unsuccessful exploitation could result in the termination of the bgpd process.
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.