5.5

CVE-2018-12066

BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bird ProjectBird Version < 1.6.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.297
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://bird.network.cz
Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900967
Third Party Advisory
Issue Tracking
https://gitlab.labs.nic.cz/labs/bird/blob/v1.6.4/NEWS#L11
Third Party Advisory
Issue Tracking
https://gitlab.labs.nic.cz/labs/bird/commit/e8bc64e308586b6502090da2775af84cd760ed0d
Patch
Third Party Advisory
Issue Tracking