Stack-Based Buffer Overflow in BIRD Internet Routing Daemon
CVE-2019-16159
7.5HIGH
What is CVE-2019-16159?
The BIRD Internet Routing Daemon encompasses a vulnerability due to a stack-based buffer overflow within its BGP daemon. The issue arises from an improper logical expression used to validate input messages associated with RFC 8203 shutdown communications. If an attacker sends a shutdown message of sufficient length, a four-byte overflow may occur during processing. Notably, two of these overflow bytes are under the attacker's control, potentially leading to severe consequences such as remote code execution or service disruption.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
