Stack-Based Buffer Overflow in BIRD Internet Routing Daemon
CVE-2019-16159

7.5HIGH

Key Information:

Vendor

Nic

Status
Vendor
CVE Published:
9 September 2019

What is CVE-2019-16159?

The BIRD Internet Routing Daemon encompasses a vulnerability due to a stack-based buffer overflow within its BGP daemon. The issue arises from an improper logical expression used to validate input messages associated with RFC 8203 shutdown communications. If an attacker sends a shutdown message of sufficient length, a four-byte overflow may occur during processing. Notably, two of these overflow bytes are under the attacker's control, potentially leading to severe consequences such as remote code execution or service disruption.

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.