Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:0457-1 Important: Quagga Remote Exploits and DoS Issues

suse
Calendar Grey February 16, 2018
Dist Suse Esm H88
The recent patch for SUSE's quagga fixes various vulnerabilities, including risks of remote code execution and denial-of-service, boosting overall system security
An update that fixes 6 vulnerabilities is now available.

Summary

This update for quagga fixes the following issues: - The Quagga BGP daemon contained a bug in the AS_PATH size calculation that could have been exploited to facilitate a remote denial-of-service attack via specially crafted BGP UPDATE messages. [CVE-2017-16227, bsc#1065641] - The Quagga BGP daemon did not check whether data sent to peers via NOTIFY had an invalid attribute length. It was possible to exploit this issue and cause the bgpd process to leak sensitive information over the network to a configured peer. [CVE-2018-5378, bsc#1079798] - The Quagga BGP daemon used to double-free memory when processing certain forms of UPDATE messages. This issue could be exploited by sending an

References

#1021669 #1065641 #1079798 #1079799 #1079800

#1079801

Cross- CVE-2017-16227 CVE-2017-5495 CVE-2018-5378

CVE-2018-5379 CVE-2018-5380 CVE-2018-5381

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-16227.html

https://www.suse.com/security/cve/CVE-2017-5495.html

https://www.suse.com/security/cve/CVE-2018-5378.html

https://www.suse.com/security/cve/CVE-2018-5379.html

https://www.suse.com/security/cve/CVE-2018-5380.html

https://www.suse.com/security/cve/CVE-2018-5381.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0457-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here