Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE 11.4 & 11.3: 2011:1155-1 Important: Quagga DoS Issues

opensuse
Calendar Grey October 18, 2011
Dist Opensuse Esm H88
openSUSE Security Update: quagga: fixing multiple vulnerabilities __________________________________
An update that fixes 5 vulnerabilities is now available

Description

This update fixes the following security issues:

- 718056: OSPF6D buffer overflow while decoding Link State

Update with Inter Area Prefix Lsa (CVE-2011-3323)

- 718058: OSPF6D DoS while decoding Database Description

packet (CVE-2011-3324)

- 718059: OSPFD DoS while decoding Hello packet

(CVE-2011-3325)

- 718061: OSPFD DoS while decoding Link State Update

(CVE-2011-3326)

- 718062: DoS while decoding EXTENDED_COMMUNITIES in

Quagga's BGP (CVE-2011-3327)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch quagga-5276

- openSUSE 11.3:

zypper in -t patch quagga-5276

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

quagga-0.99.17-4.11.1

quagga-devel-0.99.17-4.11.1

- openSUSE 11.3 (i586 x86_64) [New Version: 0.99.17]:

quagga-0.99.17-1.11.1

quagga-devel-0.99.17-1.11.1

References

https://www.suse.com/security/cve/CVE-2011-3323.html

https://www.suse.com/security/cve/CVE-2011-3324.html

https://www.suse.com/security/cve/CVE-2011-3325.html

https://www.suse.com/security/cve/CVE-2011-3326.html

https://www.suse.com/security/cve/CVE-2011-3327.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2011:1155-1
Rating: important
Affected Products: openSUSE 11.4 openSUSE 11.3 . It includes one version update.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here