Candidate: CVE-2018-12066 PublicDate: 2018-06-08 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12066 https://gitlab.labs.nic.cz/labs/bird/blob/v1.6.4/NEWS#L11 http://bird.network.cz https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900967 https://gitlab.labs.nic.cz/labs/bird/commit/e8bc64e308586b6502090da2775af84cd760ed0d Description: BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900967 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_bird: upstream_bird: released (1.6.4-1) precise/esm_bird: DNE trusty_bird: ignored (reached end-of-life) trusty/esm_bird: DNE (trusty was needs-triage) xenial_bird: ignored (end of standard support, was needs-triage) artful_bird: ignored (reached end-of-life) bionic_bird: needs-triage cosmic_bird: not-affected (1.6.4-1) disco_bird: not-affected (1.6.4-1) eoan_bird: not-affected (1.6.4-1) focal_bird: not-affected (1.6.4-1) groovy_bird: not-affected (1.6.4-1) hirsute_bird: not-affected (1.6.4-1) impish_bird: not-affected (1.6.4-1) jammy_bird: not-affected (1.6.4-1) devel_bird: not-affected (1.6.4-1)