CVE-2019-16159

    Dashboard / Vulnerabilities / CVE-2019-16159

    CVE-2019-16159

    Published: 9 Sept 2019Last Modified: 7 Aug 2026

    Summary:

    Details: BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes a four-byte overflow to occur while processing the message, where two of the overflow bytes are attacker-controlled and two are fixed.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 1e3810f9f8e251d82a8157b39df9be196315c43e
    Fixed -None

    Affected versions

    v1.6.6
    v1.6.7
    v1.6.5
    v1.6.4
    v1.6.3
    v1.6.2
    v1.6.1
    v1.6.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High