Back to Database
Status published
Medium
CVE-2006-2224
RIPd in Quagga 0.98 and 0.99 before 20060503 does not...
Vulnerability Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2224
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.novell.com/linux/security/advisories/2006_17_sr.html
- https://usn.ubuntu.com/284-1/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26251
- http://secunia.com/advisories/20782
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10775
- http://secunia.com/advisories/20138
- http://www.securityfocus.com/archive/1/432823/100/0/threaded
- http://secunia.com/advisories/20421
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
- http://www.redhat.com/support/errata/RHSA-2006-0525.html
- http://www.osvdb.org/25225
- http://secunia.com/advisories/20137
- http://securitytracker.com/id?1016204
- http://secunia.com/advisories/19910
- http://www.securityfocus.com/bid/17808
- http://www.redhat.com/support/errata/RHSA-2006-0533.html
- http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
- http://secunia.com/advisories/21159
- http://www.securityfocus.com/archive/1/432856/100/0/threaded
- http://bugzilla.quagga.net/show_bug.cgi?id=262
- http://www.debian.org/security/2006/dsa-1059
- http://secunia.com/advisories/20221
- http://secunia.com/advisories/20420
More from quagga
View All →CVE-2021-44038
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod...
High
7.8
CVE-2017-5495
All versions of Quagga, 0.93 through 1.1.0, are vulnerable to...
High
7.5
CVE-2017-16227
The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows...
High
7.5
CVE-2016-4049
The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform...
High
7.5
CVE-2016-2342
The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser...
High
8.1
Affected Vendor
quagga
View all reports →Affected Software
quagga routing software suite
Vulnerable Versions:
0, 0.95, 0.96.2, 0.96.3, 0.98.5
Timeline
Official Publish:
May 5th, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.