CVE Vulnerabilities

CVE-2006-2224

Improper Authentication

Published: May 05, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Quagga_routing_software_suite Quagga * 0.99.3 (including)
Quagga_routing_software_suite Quagga 0.95 (including) 0.95 (including)
Quagga_routing_software_suite Quagga 0.96.2 (including) 0.96.2 (including)
Quagga_routing_software_suite Quagga 0.96.3 (including) 0.96.3 (including)
Quagga_routing_software_suite Quagga 0.98.5 (including) 0.98.5 (including)
Red Hat Enterprise Linux 3 RedHat quagga-0:0.96.2-11.3E *
Red Hat Enterprise Linux 4 RedHat quagga-0:0.98.3-2.4E *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Quagga Ubuntu dapper *
Quagga Ubuntu devel *
Quagga Ubuntu edgy *
Quagga Ubuntu feisty *

Potential Mitigations

References