Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 15.10: USN-2942-1 Important: OpenSSL Vulnerability Disclosure

Ubuntu Large Esm H500
Quagga could be made to crash or run programs if it received specially crafted network traffic.
=========================================================================Ubuntu Security Notice USN-2941-1
March 24, 2016

quagga vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Quagga could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- quagga: BGP/OSPF/RIP routing daemon

Details:

Kostya Kortchinsky discovered that Quagga incorrectly handled certain route
data when configured with BGP peers enabled for VPNv4. A remote attacker
could use this issue to cause Quagga to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-2342)

It was discovered that Quagga incorrectly handled messages with a large
LSA when used in certain configurations. A remote attacker could use this
issue to cause Quagga to crash, resulting in a denial of service. This
issue only affected Ubuntu 12.04 LTS. (CVE-2013-2236)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  quagga                          0.99.24.1-2ubuntu0.1

Ubuntu 14.04 LTS:
  quagga                          0.99.22.4-3ubuntu1.1

Ubuntu 12.04 LTS:
  quagga                          0.99.20.1-0ubuntu0.12.04.4

After a standard system update you need to restart Quagga to make all the
necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2941-1
  CVE-2013-2236, CVE-2016-2342

Package Information:
  https://launchpad.net/ubuntu/+source/quagga/0.99.24.1-2ubuntu0.1
  https://launchpad.net/ubuntu/+source/quagga/0.99.22.4-3ubuntu1.1
  https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.12.04.4


Ubuntu 15.10: USN-2942-1 Important: OpenSSL Vulnerability Disclosure

ubuntu
Calendar Grey March 24, 2016
Dist Ubuntu Esm H88
The recent Ubuntu Security Announcement USN-2941-1 addresses critical vulnerabilities in the quagga networking software that may enable denial of service via malicious network packets
Quagga could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: quagga 0.99.24.1-2ubuntu0.1 Ubuntu 14.04 LTS: quagga 0.99.22.4-3ubuntu1.1 Ubuntu 12.04 LTS: quagga 0.99.20.1-0ubuntu0.12.04.4 After a standard system update you need to restart Quagga to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2941-1

CVE-2013-2236, CVE-2016-2342

Severity
important
Lowest
Low
Medium
High
Critical

March 24, 2016

Package Information

https://launchpad.net/ubuntu/+source/quagga/0.99.24.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/quagga/0.99.22.4-3ubuntu1.1 https://launchpad.net/ubuntu/+source/quagga/0.99.20.1-0ubuntu0.12.04.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here