The bgpdumproutesfunc function in bgpd/bgpdump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP packet.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4049.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "42.1" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "13.2" } ] } ]