Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 20.04: USN-7017-1: Quagga Denial Of Service Advisory

Ubuntu Large Esm H500
Quagga could be made to crash if it received specially crafted network traffic.
==========================================================================
Ubuntu Security Notice USN-7017-1
September 17, 2024

quagga vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

Quagga could be made to crash if it received specially crafted network
traffic.

Software Description:
- quagga: BGP/OSPF/RIP routing daemon

Details:

Iggy Frankovic discovered that Quagga incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause Quagga
to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
   quagga                          1.2.4-4ubuntu0.5
   quagga-bgpd                     1.2.4-4ubuntu0.5

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-7017-1
   CVE-2024-44070

Package Information:
   https://launchpad.net/ubuntu/+source/quagga/1.2.4-4ubuntu0.5

Ubuntu 20.04: USN-7017-1: Quagga Denial Of Service Advisory

ubuntu
Calendar Grey September 17, 2024
Dist Ubuntu Esm H88
A crafted network packet may trigger a failure in Quagga, leading to service interruptions on Ubuntu 20.04 LTS. It is advised to apply the latest updates.
Quagga could be made to crash if it received specially crafted network traffic.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Quagga could be made to crash if it received specially crafted network traffic. Software Description: - quagga: BGP/OSPF/RIP routing daemon Details: Iggy Frankovic discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS quagga 1.2.4-4ubuntu0.5 quagga-bgpd 1.2.4-4ubuntu0.5 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7017-1

CVE-2024-44070

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7017-1

Package Information

https://launchpad.net/ubuntu/+source/quagga/1.2.4-4ubuntu0.5

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here