Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2018:0455-1 Important Quagga Denial-of-Service Attack Fix

suse
Calendar Grey February 16, 2018
Dist Suse Esm H88
Ubuntu Security Patch for OpenSSH resolves critical weaknesses. Upgrade immediately to protect against possible attacks.
An update that fixes 6 vulnerabilities is now available.

Summary

This update for quagga fixes the following security issues: - The Quagga BGP daemon contained a bug in the AS_PATH size calculation that could have been exploited to facilitate a remote denial-of-service attack via specially crafted BGP UPDATE messages. [CVE-2017-16227, bsc#1065641] - The Quagga BGP daemon did not check whether data sent to peers via NOTIFY had an invalid attribute length. It was possible to exploit this issue and cause the bgpd process to leak sensitive information over the network to a configured peer. [CVE-2018-5378, bsc#1079798] - The Quagga BGP daemon used to double-free memory when processing certain forms of UPDATE messages. This issue could be exploited by sending an

References

#1021669 #1065641 #1079798 #1079799 #1079800

#1079801

Cross- CVE-2017-16227 CVE-2017-5495 CVE-2018-5378

CVE-2018-5379 CVE-2018-5380 CVE-2018-5381

Affected Products:

SUSE OpenStack Cloud 6

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2017-16227.html

https://www.suse.com/security/cve/CVE-2017-5495.html

https://www.suse.com/security/cve/CVE-2018-5378.html

https://www.suse.com/security/cve/CVE-2018-5379.html

https://www.suse.com/security/cve/CVE-2018-5380.html

https://www.suse.com/security/cve/CVE-2018-5381.html

https://bugzilla.suse.com/1021669

https://bugzilla.suse.com/1065641

https://bugzilla.suse.com/1079798

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0455-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here