CVE-2016-1245
9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.66% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-02-22 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| quagga | quagga |
References
- http://rhn.redhat.com/errata/RHSA-2017-0794.html
- http://www.gossamer-threads.com/lists/quagga/users/31952
- http://www.securityfocus.com/bid/93775
- https://bugzilla.redhat.com/show_bug.cgi?id=1386109
- https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546
- https://security.gentoo.org/glsa/201701-48
- https://www.debian.org/security/2016/dsa-3695
- http://rhn.redhat.com/errata/RHSA-2017-0794.html
- http://www.gossamer-threads.com/lists/quagga/users/31952
- http://www.securityfocus.com/bid/93775
- https://bugzilla.redhat.com/show_bug.cgi?id=1386109
- https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546
- https://security.gentoo.org/glsa/201701-48
- https://www.debian.org/security/2016/dsa-3695
→ the Explorer · watch your stack · NVD