← Vulnerability feed

Vulnerability record · CVE-2006-2223 · published 5 May 2006

CVE-2006-2223: Quagga improper input validation vulnerability

Quagga · Quagga

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

5.0 CVSS 2.0 Medium EPSS 11% · top 4.2% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
46References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
http://bugzilla.quagga.net/show_bug.cgi?id=261
http://secunia.com/advisories/19910 PatchVendor Advisory
http://secunia.com/advisories/20137 Vendor Advisory
http://secunia.com/advisories/20138 Vendor Advisory
http://secunia.com/advisories/20221 Vendor Advisory
http://secunia.com/advisories/20420 Vendor Advisory
http://secunia.com/advisories/20421 Vendor Advisory
http://secunia.com/advisories/20782 Vendor Advisory
http://secunia.com/advisories/21159 Vendor Advisory
http://securitytracker.com/id?1016204
http://www.debian.org/security/2006/dsa-1059
http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
http://www.novell.com/linux/security/advisories/2006_17_sr.html
http://www.osvdb.org/25224
http://www.redhat.com/support/errata/RHSA-2006-0525.html
http://www.redhat.com/support/errata/RHSA-2006-0533.html
http://www.securityfocus.com/archive/1/432822/100/0/threaded
http://www.securityfocus.com/archive/1/432823/100/0/threaded
http://www.securityfocus.com/bid/17808 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/26243
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985
https://usn.ubuntu.com/284-1/
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
http://bugzilla.quagga.net/show_bug.cgi?id=261
http://secunia.com/advisories/19910 PatchVendor Advisory
http://secunia.com/advisories/20137 Vendor Advisory
http://secunia.com/advisories/20138 Vendor Advisory
http://secunia.com/advisories/20221 Vendor Advisory
http://secunia.com/advisories/20420 Vendor Advisory
http://secunia.com/advisories/20421 Vendor Advisory
http://secunia.com/advisories/20782 Vendor Advisory
http://secunia.com/advisories/21159 Vendor Advisory
http://securitytracker.com/id?1016204
http://www.debian.org/security/2006/dsa-1059
http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
http://www.novell.com/linux/security/advisories/2006_17_sr.html
http://www.osvdb.org/25224
http://www.redhat.com/support/errata/RHSA-2006-0525.html
http://www.redhat.com/support/errata/RHSA-2006-0533.html

Track CVE-2006-2223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5379Quagga double free vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…EPSS 38%9.8CVE-2016-1245Quagga memory buffer overflow vulnerabilityIt was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…EPSS 3.7%8.2CVE-2017-3224Quagga insufficient verification of data authenticity vulnerabilityOpen Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…EPSS 1.1%8.1CVE-2016-2342Quagga memory buffer overflow vulnerabilityThe bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…EPSS 12%7.8CVE-2021-44038Quagga link following vulnerabilityAn issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-o…EPSS 0.79%7.5CVE-2018-5381Quagga vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…EPSS 30%7.5CVE-2017-16227Quagga improper input validation vulnerabilityThe aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…EPSS 19%7.5CVE-2017-5495Quagga memory buffer overflow vulnerabilityAll versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service …EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2006-2223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.