CVE-2006-2224
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 10%
from disclosure to weapon0 days
Published on NVDMay 5
1st PoCMay 3
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/27802⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.aschttp://bugzilla.quagga.net/show_bug.cgi?id=262http://secunia.com/advisories/19910http://secunia.com/advisories/20137http://secunia.com/advisories/20138http://secunia.com/advisories/20221http://secunia.com/advisories/20420http://secunia.com/advisories/20421http://secunia.com/advisories/20782http://secunia.com/advisories/21159http://securitytracker.com/id?1016204https://exchange.xforce.ibmcloud.com/vulnerabilities/26251