Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Ubuntu 20.04: 2022-acbdef1234 Urgent: BIND Memory Leak Patch

fedora
Calendar Grey March 6, 2018
Dist Fedora Esm H88
To resolve the double free problem in Quagga's bgpd on Fedora 27, analyze memory management for safe allocation and deallocation, ensuring security
Fixed CVE-2018-5379 - Double free vulnerability in bgpd when processing

Summary

Quagga is free software that operates TCP/IP-based routing protocols. It takes

a multi-server and multi-threaded approach to resolving the current complexity

of the Internet.

Quagga supports Babel, BGP4, BGP4+, BGP4-, IS-IS (experimental), OSPFv2,

OSPFv3, RIPv1, RIPv2, RIPng, PIM-SSM and NHRP.

Quagga is intended to be used as a Route Server and a Route Reflector. It is

not a toolkit; it provides full routing power under a new architecture.

Quagga by design has a process for each protocol.

Quagga is a fork of GNU Zebra.

Fixed CVE-2018-5379 - Double free vulnerability in bgpd when processing

[ 1 ] Bug #1546008 - CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1546008

[ 2 ] Bug #1546006 - CVE-2018-5380 quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1546006

[ 3 ] Bug #1546004 - CVE-2018-5381 quagga: Infinite loop issue triggered by invalid OPEN message allows denial-of-service [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1546004

[ 4 ] Bug #1546009 - CVE-2018-5378 quagga: bgpd does not properly bounds check the data sent with a NOTIFY allowing leak of sensitive data or crash [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1546009

su -c 'dnf upgrade quagga' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 1.2.2
Release: 2.fc27
URL: Summary : Routing daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here