This update for quagga fixes the following issues: - The Quagga BGP daemon contained a bug in the AS_PATH size calculation that could have been exploited to facilitate a remote denial-of-service attack via specially crafted BGP UPDATE messages. [CVE-2017-16227, bsc#1065641] - The Quagga BGP daemon did not check whether data sent to peers via NOTIFY had an invalid attribute length. It was possible to exploit this issue and cause the bgpd process to leak sensitive information over the network to a configured peer. [CVE-2018-5378, bsc#1079798] - The Quagga BGP daemon used to double-free memory when processing certain forms of UPDATE messages. This issue could be exploited by sending an
#1021669 #1065641 #1079798 #1079799 #1079800
#1079801
Cross- CVE-2017-16227 CVE-2017-5495 CVE-2018-5378
CVE-2018-5379 CVE-2018-5380 CVE-2018-5381
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-SP3-LTSS
SUSE Linux Enterprise Point of Sale 11-SP3
SUSE Linux Enterprise Debuginfo 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP3
https://www.suse.com/security/cve/CVE-2017-16227.html
https://www.suse.com/security/cve/CVE-2017-5495.html
https://www.suse.com/security/cve/CVE-2018-5378.html
https://www.suse.com/security/cve/CVE-2018-5379.html
https://www.suse.com/security/cve/CVE-2018-5380.html
https://www.suse.com/security/cve/CVE-2018-5381.html
Get the latest Linux and open source security news straight to your inbox.