CVE-2006-2224 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 10.4% (pctl 96)
Patch early
A public exploit exists.
Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 10.36% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-05-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| quagga | quagga routing software suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Quagga Routing Software Suite 0.9x - RIPd RIPv1 RESPONSE Packet Route Injection | 2006-05-03 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
- http://bugzilla.quagga.net/show_bug.cgi?id=262
- http://secunia.com/advisories/19910
- http://secunia.com/advisories/20137
- http://secunia.com/advisories/20138
- http://secunia.com/advisories/20221
- http://secunia.com/advisories/20420
- http://secunia.com/advisories/20421
- http://secunia.com/advisories/20782
- http://secunia.com/advisories/21159
- http://securitytracker.com/id?1016204
- http://www.debian.org/security/2006/dsa-1059
- http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
- http://www.novell.com/linux/security/advisories/2006_17_sr.html
- http://www.osvdb.org/25225
- http://www.redhat.com/support/errata/RHSA-2006-0525.html
- http://www.redhat.com/support/errata/RHSA-2006-0533.html
- http://www.securityfocus.com/archive/1/432823/100/0/threaded
- http://www.securityfocus.com/archive/1/432856/100/0/threaded
- http://www.securityfocus.com/bid/17808
→ the Explorer · watch your stack · NVD