CVE-2012-0250: Quagga

Low severity, CVSS 3.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.

Affected products

  • Quagga Quagga: up to and including 0.99.20; version 0.99.1 only; version 0.99.2 only; version 0.99.3 only; version 0.99.4 only; version 0.99.5 only; …

Published 2012-04-05. Last modified 2026-06-16.