CVE-2012-0249

low
Published 2012-04-05 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
3.3

Description

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
quaggaquagga{"endIncluding":"0.99.20"}
quaggaquagga0.95
quaggaquagga0.96
quaggaquagga0.96.1
quaggaquagga0.96.2
quaggaquagga0.96.3
quaggaquagga0.96.4
quaggaquagga0.96.5
quaggaquagga0.97.0
quaggaquagga0.97.1
quaggaquagga0.97.2
quaggaquagga0.97.3
quaggaquagga0.97.4
quaggaquagga0.97.5
quaggaquagga0.98.0
quaggaquagga0.98.1
quaggaquagga0.98.2
quaggaquagga0.98.3
quaggaquagga0.98.4
quaggaquagga0.98.5
quaggaquagga0.98.6
quaggaquagga0.99.1
quaggaquagga0.99.2
quaggaquagga0.99.3
quaggaquagga0.99.4
quaggaquagga0.99.5
quaggaquagga0.99.6
quaggaquagga0.99.7
quaggaquagga0.99.8
quaggaquagga0.99.9
quaggaquagga0.99.10
quaggaquagga0.99.11
quaggaquagga0.99.12
quaggaquagga0.99.13
quaggaquagga0.99.14
quaggaquagga0.99.15
quaggaquagga0.99.16
quaggaquagga0.99.17
quaggaquagga0.99.18
quaggaquagga0.99.19

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.