CVE-2006-2224 Information
Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Reference
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc http://bugzilla.quagga.net/show_bug.cgi?id=262 http://secunia.com/advisories/19910 http://secunia.com/advisories/20137 http://secunia.com/advisories/20138 http://secunia.com/advisories/20221 http://secunia.com/advisories/20420 http://secunia.com/advisories/20421 http://secunia.com/advisories/20782 http://secunia.com/advisories/21159 http://securitytracker.com/id?1016204 http://www.debian.org/security/2006/dsa-1059 http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml http://www.novell.com/linux/security/advisories/2006_17_sr.html http://www.osvdb.org/25225 http://www.redhat.com/support/errata/RHSA-2006-0525.html http://www.redhat.com/support/errata/RHSA-2006-0533.html http://www.securityfocus.com/archive/1/432823/100/0/threaded http://www.securityfocus.com/archive/1/432856/100/0/threaded http://www.securityfocus.com/bid/17808 https://exchange.xforce.ibmcloud.com/vulnerabilities/26251 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10775 https://usn.ubuntu.com/284-1/
Share on: