Paketname
quagga
Datum
2007-05-02
Advisory ID
MDKSA-2007:096
Betroffene Versionen
CS4.0 x86_64 , CS4.0 i586

Problembeschreibung

The BGP routing daemon in Quagga did not properly validate length
values in NLRI attributes which could allow a remote attacker to cause
a denial of service via a crafted UPDATE message that triggered an
assertion error or out of bounds read.

Updated packages have been patched to correct this issue.

Aktualisierte Pakete

CS4.0 x86_64

 92d1d28d06eb4eaff483882a41a5d31b  corporate/4.0/x86_64/lib64quagga0-0.99.3-1.1.20060mlcs4.x86_64.rpm
 ccfa5e5665423f19b0c36ff13db53164  corporate/4.0/x86_64/lib64quagga0-devel-0.99.3-1.1.20060mlcs4.x86_64.rpm
 a9af90e11e1b9f0485718d4762b1f8fd  corporate/4.0/x86_64/quagga-0.99.3-1.1.20060mlcs4.x86_64.rpm
 596581e4051d2e02ae2b476e3aa83f74  corporate/4.0/x86_64/quagga-contrib-0.99.3-1.1.20060mlcs4.x86_64.rpm 
 725cf792adafc90d58a34178e4066771  corporate/4.0/SRPMS/quagga-0.99.3-1.1.20060mlcs4.src.rpm

CS4.0 i586

 becaf6ded7283c9c6021b225cdf4610a  corporate/4.0/i586/libquagga0-0.99.3-1.1.20060mlcs4.i586.rpm
 71834dab731b65e7a35a9fdd9732a889  corporate/4.0/i586/libquagga0-devel-0.99.3-1.1.20060mlcs4.i586.rpm
 cfbeb9e74071ffac712e5162f2613ac9  corporate/4.0/i586/quagga-0.99.3-1.1.20060mlcs4.i586.rpm
 7cde7b9c156b90b8dcc960bfc1e32cbe  corporate/4.0/i586/quagga-contrib-0.99.3-1.1.20060mlcs4.i586.rpm 
 725cf792adafc90d58a34178e4066771  corporate/4.0/SRPMS/quagga-0.99.3-1.1.20060mlcs4.src.rpm

Referenzen