Executive brief
Quagga is a software suite used to manage network routing protocols like BGP and OSPF. A vulnerability in its management interface allows an unauthenticated attacker to crash the routing service or the entire server by sending specially crafted, long text strings. This can lead to a complete loss of network connectivity and service availability for the affected infrastructure.
Technical details
A vulnerability exists in the 'vty' telnet CLI component of Quagga and early versions of FRRouting due to improper restriction of memory buffer operations (CWE-119). The input buffer for the telnet interface is designed to grow automatically without a hard limit until a newline character is received. An unauthenticated remote attacker with network access to the TCP ports used by Quagga daemons can send an extremely long string without a newline, causing the process to allocate all available system memory. This results in the daemon being killed by the OOM (Out of Memory) killer or a total system crash. The issue is resolved in Quagga 1.1.1 and FRR 2017-01-10 by implementing a 4096-byte cap on the vty buffer.
Affected products
- Quagga Quagga 0.93 through 1.1.0
- FRRouting FRRouting (FRR) Protocol Suite Prior to 2017-01-10
Timeline
- 2017-01-10: patched: FRRouting fix merged
- 2017-01-24: disclosed: Public disclosure of CVE-2017-5495
- 2017-01-24: advisory: NVD published date
References
- http://rhn.redhat.com/errata/RHSA-2017-0794.html
- http://savannah.nongnu.org/forum/forum.php?forum_id=8783
- http://www.securityfocus.com/bid/95745
- http://www.securitytracker.com/id/1037688
- https://github.com/freerangerouting/frr/pull/63
- https://lists.quagga.net/pipermail/quagga-dev/2017-January/016586.html