← Back to browse · API

CVE-2018-5378

Severity
HIGH
CVSS
7.1
EPSS
0.742
Risk score
54.37
CISA KEV
No
PoC
No
Published
2018-02-19
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2018-17150, GHSA-529C-38P9-5C53
Products
quagga:bgpd bpgd <1.2.3
Sources
euvd EUVD-2018-17150

Description

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

References