CVE-2012-0249: Quagga

Low severity, CVSS 3.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.

Affected products

  • Quagga Quagga: up to and including 0.99.20; version 0.95 only; version 0.96 only; version 0.96.1 only; version 0.96.2 only; version 0.96.3 only; …

Published 2012-04-05. Last modified 2026-06-16.