RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
| Software | From | Fixed in |
|---|---|---|
| quagga / quagga_routing_software_suite | 0.98.5 | 0.98.5.x |
| quagga / quagga_routing_software_suite | 0.96.3 | 0.96.3.x |
| quagga / quagga_routing_software_suite | 0.95 | 0.95.x |
| quagga / quagga_routing_software_suite | 0.96.2 | 0.96.2.x |
| quagga / quagga_routing_software_suite | - | 0.99.3.x |