Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 11.10 USN-1261-1 Moderate Quagga Denial Of Service

ubuntu
Calendar Grey November 15, 2011
Scroller Ubuntu
The vulnerabilities in Quagga permit distant adversaries to induce system crashes or run arbitrary code through specially crafted packets, impacting various versions of Ubuntu.
Quagga could be made to crash or run programs if it received specially crafted network traffic.

Summary

Quagga could be made to crash or run programs if it received specially

crafted network traffic.

Software Description:

- quagga: BGP/OSPF/RIP routing daemon

Details:

Riku Hietamäki, Tuomo Untinen and Jukka Taimisto discovered that Quagga

incorrectly handled Link State Update messages with invalid lengths. A

remote attacker could use this flaw to cause Quagga to crash, resulting in

a denial of service. (CVE-2011-3323)

Riku Hietamäki, Tuomo Untinen and Jukka Taimisto discovered that Quagga

incorrectly handled certain IPv6 Database Description messages. A remote

attacker could use this flaw to cause Quagga to crash, resulting in a

denial of service. (CVE-2011-3324)

Riku Hietamäki, Tuomo Untinen and Jukka Taimisto discovered that Quagga

incorrectly handled certain IPv4 packets. A remote attacker could use this

flaw to cause Quagga to crash, resulting in a denial of service.

(CVE-2011-3325)

Riku Hietamäki, Tuomo Untinen and Jukka Taimisto discovered that...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  quagga                          0.99.18-2ubuntu0.1

Ubuntu 11.04:
  quagga                          0.99.17-4ubuntu1.1

Ubuntu 10.10:
  quagga                          0.99.17-1ubuntu0.2

Ubuntu 10.04 LTS:
  quagga                          0.99.15-1ubuntu0.3

In general, a standard system update will make all the necessary changes.

References

CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, CVE-2011-3326,

CVE-2011-3327

November 14, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.