The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "quagga", "binary_version": "0.99.22.4-3ubuntu1.5" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-5380.json"
{ "availability": "No subscription required", "binaries": [ { "binary_name": "quagga", "binary_version": "0.99.24.1-2ubuntu1.4" } ] }