RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Quagga_routing_software_suite | Quagga | * | 0.99.3 (including) |
Quagga_routing_software_suite | Quagga | 0.95 (including) | 0.95 (including) |
Quagga_routing_software_suite | Quagga | 0.96.2 (including) | 0.96.2 (including) |
Quagga_routing_software_suite | Quagga | 0.96.3 (including) | 0.96.3 (including) |
Quagga_routing_software_suite | Quagga | 0.98.5 (including) | 0.98.5 (including) |
Red Hat Enterprise Linux 3 | RedHat | quagga-0:0.96.2-11.3E | * |
Red Hat Enterprise Linux 4 | RedHat | quagga-0:0.98.3-2.4E | * |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Quagga | Ubuntu | dapper | * |
Quagga | Ubuntu | devel | * |
Quagga | Ubuntu | edgy | * |
Quagga | Ubuntu | feisty | * |