Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-16159

BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes a four-byte overflow to occur while processing the message, where two of the overflow bytes are attacker-controlled and two are fixed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2019-16159
  • Nic » Bird » Version: 1.6.0
    cpe:2.3:a:nic:bird:1.6.0
  • Nic » Bird » Version: 1.6.1
    cpe:2.3:a:nic:bird:1.6.1
  • Nic » Bird » Version: 1.6.2
    cpe:2.3:a:nic:bird:1.6.2
  • Nic » Bird » Version: 1.6.3
    cpe:2.3:a:nic:bird:1.6.3
  • Nic » Bird » Version: 1.6.4
    cpe:2.3:a:nic:bird:1.6.4
  • Nic » Bird » Version: 1.6.5
    cpe:2.3:a:nic:bird:1.6.5
  • Nic » Bird » Version: 1.6.6
    cpe:2.3:a:nic:bird:1.6.6
  • Nic » Bird » Version: 1.6.7
    cpe:2.3:a:nic:bird:1.6.7
  • Nic » Bird » Version: 2.0.0
    cpe:2.3:a:nic:bird:2.0.0
  • Nic » Bird » Version: 2.0.1
    cpe:2.3:a:nic:bird:2.0.1
  • Nic » Bird » Version: 2.0.2
    cpe:2.3:a:nic:bird:2.0.2
  • Nic » Bird » Version: 2.0.3
    cpe:2.3:a:nic:bird:2.0.3
  • Nic » Bird » Version: 2.0.4
    cpe:2.3:a:nic:bird:2.0.4
  • Nic » Bird » Version: 2.0.5
    cpe:2.3:a:nic:bird:2.0.5
  • Opensuse » Backports Sle » Version: 15.0
    cpe:2.3:a:opensuse:backports_sle:15.0
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Fedoraproject » Fedora » Version: 29
    cpe:2.3:o:fedoraproject:fedora:29
  • Fedoraproject » Fedora » Version: 30
    cpe:2.3:o:fedoraproject:fedora:30


Contact Us

Shodan ® - All rights reserved