Security Advisory

CVE-2017-16227

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-29 20:00:00
Last updated 2024-08-05 20:20:04
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequently constructs an invalid message.