CVE-2009-1572
quagga - denial of service
EPSS 3.5%
Description
The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert error.
How to fix CVE-2009-1572
To remediate CVE-2009-1572, upgrade the affected package to a fixed version below.
- Debian/quagga—upgrade to 0.99.11-2 or later
- Debian/quagga—upgrade to 0.99.10-1lenny2 or later
Is CVE-2009-1572 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.99.11-2
- from 0, < 0.99.10-1lenny2