CVE Vulnerabilities

CVE-2006-2224

Improper Authentication

Published: May 05, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Quagga_routing_software_suiteQuagga*0.99.3 (including)
Quagga_routing_software_suiteQuagga0.95 (including)0.95 (including)
Quagga_routing_software_suiteQuagga0.96.2 (including)0.96.2 (including)
Quagga_routing_software_suiteQuagga0.96.3 (including)0.96.3 (including)
Quagga_routing_software_suiteQuagga0.98.5 (including)0.98.5 (including)
Red Hat Enterprise Linux 3RedHatquagga-0:0.96.2-11.3E*
Red Hat Enterprise Linux 4RedHatquagga-0:0.98.3-2.4E*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
QuaggaUbuntudapper*
QuaggaUbuntudevel*
QuaggaUbuntuedgy*
QuaggaUbuntufeisty*

Potential Mitigations

References