← Vulnerability feed

Vulnerability record · CVE-2010-1674 · published 29 March 2011

CVE-2010-1674: Quagga vulnerability

Quagga · Quagga

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.

5.0 CVSS 2.0 Medium EPSS 13% · top 3.7%
5.0CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00009.html
http://rhn.redhat.com/errata/RHSA-2012-1258.html
http://secunia.com/advisories/43499 Vendor Advisory
http://secunia.com/advisories/43770 Vendor Advisory
http://secunia.com/advisories/48106
http://security.gentoo.org/glsa/glsa-201202-02.xml
http://www.debian.org/security/2011/dsa-2197
http://www.mandriva.com/security/advisories?name=MDVSA-2011:058
http://www.osvdb.org/71259
http://www.quagga.net/news2.php?y=2011&m=3&d=21#id1300723200
http://www.securityfocus.com/bid/46942
http://www.vupen.com/english/advisories/2011/0711 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=654603
https://exchange.xforce.ibmcloud.com/vulnerabilities/66211
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00009.html
http://rhn.redhat.com/errata/RHSA-2012-1258.html
http://secunia.com/advisories/43499 Vendor Advisory
http://secunia.com/advisories/43770 Vendor Advisory
http://secunia.com/advisories/48106
http://security.gentoo.org/glsa/glsa-201202-02.xml
http://www.debian.org/security/2011/dsa-2197
http://www.mandriva.com/security/advisories?name=MDVSA-2011:058
http://www.osvdb.org/71259
http://www.quagga.net/news2.php?y=2011&m=3&d=21#id1300723200
http://www.securityfocus.com/bid/46942
http://www.vupen.com/english/advisories/2011/0711 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=654603
https://exchange.xforce.ibmcloud.com/vulnerabilities/66211

Track CVE-2010-1674 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5379Quagga double free vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…EPSS 38%9.8CVE-2016-1245Quagga memory buffer overflow vulnerabilityIt was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…EPSS 3.7%8.2CVE-2017-3224Quagga insufficient verification of data authenticity vulnerabilityOpen Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…EPSS 1.1%8.1CVE-2016-2342Quagga memory buffer overflow vulnerabilityThe bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…EPSS 12%7.8CVE-2021-44038Quagga link following vulnerabilityAn issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-o…EPSS 0.79%7.5CVE-2018-5381Quagga vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…EPSS 30%7.5CVE-2017-16227Quagga improper input validation vulnerabilityThe aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…EPSS 19%7.5CVE-2017-5495Quagga memory buffer overflow vulnerabilityAll versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service …EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2010-1674), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.