Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Quagga could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7230-1 January 27, 2025 quagga vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Quagga could be made to crash if it received specially crafted network traffic. Software Description: - quagga: BGP/OSPF/RIP routing daemon Details: Iggy Frankovic discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS quagga 1.2.4-1ubuntu0.1~esm2 Available with Ubuntu Pro quagga-bgpd 1.2.4-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7230-1 CVE-2024-44070 . Debian publishes an urgent notice regarding a netfilter flaw compromising security through malicious packets.. quagga updates, Ubuntu advisory, network security, DoS protection. . Severity: Critical. LinuxSecurity.com Team
* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References: . # Security update for quagga Announcement ID: SUSE-SU-2024:3478-1 Rating: important References: * bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References: * CVE-2017-15865 * CVE-2022-37032 * CVE-2024-44070 CVSS scores: * CVE-2017-15865 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2017-15865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2017-15865 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-37032 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2022-37032 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-44070 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44070 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-44070 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * Server Applications Module 15-SP5 * Server Applications Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: Thisupdate for quagga fixes the following issues: * CVE-2017-15865: sensitive information disclosed when malformed BGP UPDATE packets are processed. (bsc#1230866) * CVE-2024-44070: crash when parsing Tunnel Encap attribute due to no length check. (bsc#1229438) * CVE-2022-37032: out-of-bounds read when parsing a BGP capability message due to incorrect size check. (bsc#1202023) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-3478=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3478=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3478=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-3478=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-3478=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3478=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3478=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3478=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3478=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-3478=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-3478=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-3478=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 *libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 *libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Manager Proxy 4.3 (x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 *libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * quagga-1.1.1-150400.12.8.1 * libospf0-1.1.1-150400.12.8.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.8.1 * libzebra1-debuginfo-1.1.1-150400.12.8.1 * libospfapiclient0-1.1.1-150400.12.8.1 * libfpm_pb0-1.1.1-150400.12.8.1 * quagga-debugsource-1.1.1-150400.12.8.1 * libospf0-debuginfo-1.1.1-150400.12.8.1 * quagga-devel-1.1.1-150400.12.8.1 * quagga-debuginfo-1.1.1-150400.12.8.1 * libquagga_pb0-1.1.1-150400.12.8.1 * libzebra1-1.1.1-150400.12.8.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.8.1 ## References: * https://www.suse.com/security/cve/CVE-2017-15865.html * https://www.suse.com/security/cve/CVE-2022-37032.html * https://www.suse.com/security/cve/CVE-2024-44070.html * https://bugzilla.suse.com/show_bug.cgi?id=1202023 *https://bugzilla.suse.com/show_bug.cgi?id=1229438 * https://bugzilla.suse.com/show_bug.cgi?id=1230866 . SUSE has released an important security advisory providing necessary updates for quagga, effectively tackling severe vulnerabilities that cause system crashes and potential data leaks.. quagga security advisory, SUSE important update, SUSE Linux vulnerabilities, quagga patch, buffer overflow. . Severity: Important. LinuxSecurity.com Team
* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References: . # Security update for quagga Announcement ID: SUSE-SU-2024:3433-1 Rating: important References: * bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References: * CVE-2017-15865 * CVE-2022-37032 * CVE-2024-44070 CVSS scores: * CVE-2017-15865 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2017-15865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2017-15865 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-37032 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2022-37032 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-44070 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44070 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-44070 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for quagga fixes the following issues: * CVE-2017-15865: sensitive information disclosed when malformed BGP UPDATE packets are processed. (bsc#1230866) * CVE-2024-44070: crash when parsing Tunnel Encap attribute due to no length check. (bsc#1229438) * CVE-2022-37032: out-of-bounds read when parsing a BGP capabilitymessage due to incorrect size check. (bsc#1202023) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-3433=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3433=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-3433=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3433=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-3433=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3433=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3433=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 *quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 *libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * libospfapiclient0-debuginfo-1.1.1-150000.4.6.1 * libquagga_pb0-debuginfo-1.1.1-150000.4.6.1 * quagga-devel-1.1.1-150000.4.6.1 * libzebra1-1.1.1-150000.4.6.1 * libzebra1-debuginfo-1.1.1-150000.4.6.1 * quagga-debuginfo-1.1.1-150000.4.6.1 * libospf0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-debuginfo-1.1.1-150000.4.6.1 * libfpm_pb0-1.1.1-150000.4.6.1 * libquagga_pb0-1.1.1-150000.4.6.1 * quagga-1.1.1-150000.4.6.1 * libospf0-1.1.1-150000.4.6.1 * quagga-debugsource-1.1.1-150000.4.6.1 * libospfapiclient0-1.1.1-150000.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2017-15865.html * https://www.suse.com/security/cve/CVE-2022-37032.html * https://www.suse.com/security/cve/CVE-2024-44070.html * https://bugzilla.suse.com/show_bug.cgi?id=1202023 * https://bugzilla.suse.com/show_bug.cgi?id=1229438 *https://bugzilla.suse.com/show_bug.cgi?id=1230866 . Important SUSE patch addresses various vulnerabilities in quagga, safeguarding system stability. Update your systems today!. quagga update,SUSE security advisory,networking security,system integrity,patch management. . Severity: Important. LinuxSecurity.com Team
* bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801 . # Security update for quagga Announcement ID: SUSE-SU-2024:3426-1 Rating: important References: * bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801 * bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References: * CVE-2017-15865 * CVE-2018-5378 * CVE-2018-5379 * CVE-2018-5380 * CVE-2018-5381 * CVE-2022-37032 * CVE-2024-44070 CVSS scores: * CVE-2017-15865 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2017-15865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2017-15865 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2018-5378 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2018-5379 ( NVD ): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2018-5380 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2018-5381 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-37032 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2022-37032 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-44070 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44070 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-44070 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves seven vulnerabilities and has one security fix can now be installed. ## Description: This update for quagga fixes the following issues: * CVE-2017-15865: sensitive information disclosed when malformed BGP UPDATE packets are processed. (bsc#1230866) * CVE-2024-44070: crash when parsing Tunnel Encapattribute due to no length check. (bsc#1229438) * CVE-2022-37032: out-of-bounds read when parsing a BGP capability message due to incorrect size check. (bsc#1202023) Bug fixes: \- References to /var/adm/fillup-templates replaced with new %_fillupdir macro. (bsc#1069468) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3426=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3426=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3426=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3426=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libfpm_pb0-debuginfo-1.1.1-17.13.1 * libzebra1-1.1.1-17.13.1 * quagga-debugsource-1.1.1-17.13.1 * libfpm_pb0-1.1.1-17.13.1 * libzebra1-debuginfo-1.1.1-17.13.1 * libospfapiclient0-1.1.1-17.13.1 * quagga-debuginfo-1.1.1-17.13.1 * libquagga_pb0-debuginfo-1.1.1-17.13.1 * libospf0-1.1.1-17.13.1 * libospfapiclient0-debuginfo-1.1.1-17.13.1 * libquagga_pb0-1.1.1-17.13.1 * quagga-1.1.1-17.13.1 * libospf0-debuginfo-1.1.1-17.13.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libfpm_pb0-debuginfo-1.1.1-17.13.1 * libzebra1-1.1.1-17.13.1 * quagga-debugsource-1.1.1-17.13.1 * libfpm_pb0-1.1.1-17.13.1 * libzebra1-debuginfo-1.1.1-17.13.1 * libospfapiclient0-1.1.1-17.13.1 * quagga-debuginfo-1.1.1-17.13.1 * libquagga_pb0-debuginfo-1.1.1-17.13.1 * libospf0-1.1.1-17.13.1 * libospfapiclient0-debuginfo-1.1.1-17.13.1 * libquagga_pb0-1.1.1-17.13.1 * quagga-1.1.1-17.13.1 *libospf0-debuginfo-1.1.1-17.13.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libfpm_pb0-debuginfo-1.1.1-17.13.1 * libzebra1-1.1.1-17.13.1 * quagga-debugsource-1.1.1-17.13.1 * libfpm_pb0-1.1.1-17.13.1 * libzebra1-debuginfo-1.1.1-17.13.1 * libospfapiclient0-1.1.1-17.13.1 * quagga-debuginfo-1.1.1-17.13.1 * libquagga_pb0-debuginfo-1.1.1-17.13.1 * libospf0-1.1.1-17.13.1 * libospfapiclient0-debuginfo-1.1.1-17.13.1 * libquagga_pb0-1.1.1-17.13.1 * quagga-1.1.1-17.13.1 * libospf0-debuginfo-1.1.1-17.13.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * quagga-debugsource-1.1.1-17.13.1 * quagga-debuginfo-1.1.1-17.13.1 * quagga-devel-1.1.1-17.13.1 ## References: * https://www.suse.com/security/cve/CVE-2017-15865.html * https://www.suse.com/security/cve/CVE-2018-5378.html * https://www.suse.com/security/cve/CVE-2018-5379.html * https://www.suse.com/security/cve/CVE-2018-5380.html * https://www.suse.com/security/cve/CVE-2018-5381.html * https://www.suse.com/security/cve/CVE-2022-37032.html * https://www.suse.com/security/cve/CVE-2024-44070.html * https://bugzilla.suse.com/show_bug.cgi?id=1069468 * https://bugzilla.suse.com/show_bug.cgi?id=1079798 * https://bugzilla.suse.com/show_bug.cgi?id=1079799 * https://bugzilla.suse.com/show_bug.cgi?id=1079800 * https://bugzilla.suse.com/show_bug.cgi?id=1079801 * https://bugzilla.suse.com/show_bug.cgi?id=1202023 * https://bugzilla.suse.com/show_bug.cgi?id=1229438 * https://bugzilla.suse.com/show_bug.cgi?id=1230866 . Critical SUSE upgrade for quagga resolves numerous concerns and vulnerabilities, enhancing overall system security and reliability.. SUSE Update, Quagga Security, Important Patch, System Safety. . Severity: Important. LinuxSecurity.com Team
This update for quagga fixes the following issues: CVE-2023-38802: Fixed bad length handling in BGP attribute handling (bsc#1213284).. # Security update for quagga Announcement ID: SUSE-SU-2023:3839-1 Rating: important References: * #1213284 * #1214735 Cross-References: * CVE-2023-38802 * CVE-2023-41358 CVSS scores: * CVE-2023-38802 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-38802 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-41358 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-41358 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP4 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for quagga fixes the following issues: * CVE-2023-38802: Fixed bad length handling in BGP attribute handling (bsc#1213284). * CVE-2023-41358: Fixed possible crash when processing NLRIs if the attribute length is zero (bsc#1214735). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-3839=1 openSUSE-SLE-15.4-2023-3839=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3839=1 *Server Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2023-3839=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2023-3839=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * quagga-debugsource-1.1.1-150400.12.5.1 * libzebra1-debuginfo-1.1.1-150400.12.5.1 * quagga-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.5.1 * libospf0-1.1.1-150400.12.5.1 * quagga-devel-1.1.1-150400.12.5.1 * libquagga_pb0-1.1.1-150400.12.5.1 * quagga-1.1.1-150400.12.5.1 * libfpm_pb0-1.1.1-150400.12.5.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.5.1 * libzebra1-1.1.1-150400.12.5.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.5.1 * libospf0-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-1.1.1-150400.12.5.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * quagga-debugsource-1.1.1-150400.12.5.1 * libzebra1-debuginfo-1.1.1-150400.12.5.1 * quagga-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.5.1 * libospf0-1.1.1-150400.12.5.1 * quagga-devel-1.1.1-150400.12.5.1 * libquagga_pb0-1.1.1-150400.12.5.1 * quagga-1.1.1-150400.12.5.1 * libfpm_pb0-1.1.1-150400.12.5.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.5.1 * libzebra1-1.1.1-150400.12.5.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.5.1 * libospf0-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-1.1.1-150400.12.5.1 * Server Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * quagga-debugsource-1.1.1-150400.12.5.1 * libzebra1-debuginfo-1.1.1-150400.12.5.1 * quagga-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.5.1 * libospf0-1.1.1-150400.12.5.1 * quagga-devel-1.1.1-150400.12.5.1 * libquagga_pb0-1.1.1-150400.12.5.1 * quagga-1.1.1-150400.12.5.1 * libfpm_pb0-1.1.1-150400.12.5.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.5.1 *libzebra1-1.1.1-150400.12.5.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.5.1 * libospf0-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-1.1.1-150400.12.5.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * quagga-debugsource-1.1.1-150400.12.5.1 * libzebra1-debuginfo-1.1.1-150400.12.5.1 * quagga-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.5.1 * libospf0-1.1.1-150400.12.5.1 * quagga-devel-1.1.1-150400.12.5.1 * libquagga_pb0-1.1.1-150400.12.5.1 * quagga-1.1.1-150400.12.5.1 * libfpm_pb0-1.1.1-150400.12.5.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.5.1 * libzebra1-1.1.1-150400.12.5.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.5.1 * libospf0-debuginfo-1.1.1-150400.12.5.1 * libospfapiclient0-1.1.1-150400.12.5.1 ## References: * https://www.suse.com/security/cve/CVE-2023-38802.html * https://www.suse.com/security/cve/CVE-2023-41358.html * https://bugzilla.suse.com/show_bug.cgi?id=1213284 * https://bugzilla.suse.com/show_bug.cgi?id=1214735 . This patch resolves important vulnerabilities in Quagga for Fedora, particularly improvements in OSPF protocol management.. Quagga Security Patch, openSUSE Update, Networking Threats. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201804-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Quagga: Multiple vulnerabilities Date: April 22, 2018 Bugs: #647788 ID: 201804-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code. Background ========= Quagga is a free routing daemon replacing Zebra supporting RIP, OSPF and BGP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/quagga < 1.2.4 > = 1.2.4 Description ========== Multiple vulnerabilities have been discovered in Quagga. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker, by sending specially crafted packets, could execute arbitrary code or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Quagga users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/quagga-1.2.4" References ========= [ 1 ] CVE-2018-5378 https://nvd.nist.gov/vuln/detail/CVE-2018-5378 [ 2 ] CVE-2018-5379 https://nvd.nist.gov/vuln/detail/CVE-2018-5379 [ 3 ] CVE-2018-5380 https://nvd.nist.gov/vuln/detail/CVE-2018-5380 [ 4 ] CVE-2018-5381 https://nvd.nist.gov/vuln/detail/CVE-2018-5381 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201804-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Upstream details at : https://access.redhat.com/errata/RHSA-2018:0377. CentOS Errata and Security Advisory 2018:0377 Important Upstream details at : https://access.redhat.com/errata/RHSA-2018:0377 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: fc6365b8be5a0f09b1c7906a4e32460414fd98b941adbd0abdb9a5054a9ef9f8 quagga-0.99.22.4-5.el7_4.i686.rpm bb7a7b2c73271fa3ed56def5ada5ef5618c64222de4119f9e765c7ae3a90a1b7 quagga-0.99.22.4-5.el7_4.x86_64.rpm 3993c187f182e98af3e539c60f28c5815e3e081490d23b3fe16ee0b9b09c18fd quagga-contrib-0.99.22.4-5.el7_4.x86_64.rpm ed24c6cba7edd850c9a07376abfe5a648a48848d5f1d77d8911bd3867e9856c4 quagga-devel-0.99.22.4-5.el7_4.i686.rpm 98c5d9a54b49554af7e9749e7e431288c8e95fa653d3563fc6f352a5bfbf7479 quagga-devel-0.99.22.4-5.el7_4.x86_64.rpm Source: f078810b4dfb5361a04366c71cd6bf78970dfe54d3500d3fdadb76998c7f3cb6 quagga-0.99.22.4-5.el7_4.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Fixed CVE-2018-5379 - Double free vulnerability in bgpd when processing. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-9cd3ff3784 2018-03-06 17:17:51.856062 --------------------------------------------------------------------------------Name : quagga Product : Fedora 27 Version : 1.2.2 Release : 2.fc27 URL : Summary : Routing daemon Description : Quagga is free software that operates TCP/IP-based routing protocols. It takes a multi-server and multi-threaded approach to resolving the current complexity of the Internet. Quagga supports Babel, BGP4, BGP4+, BGP4-, IS-IS (experimental), OSPFv2, OSPFv3, RIPv1, RIPv2, RIPng, PIM-SSM and NHRP. Quagga is intended to be used as a Route Server and a Route Reflector. It is not a toolkit; it provides full routing power under a new architecture. Quagga by design has a process for each protocol. Quagga is a fork of GNU Zebra. --------------------------------------------------------------------------------Update Information: Fixed CVE-2018-5379 - Double free vulnerability in bgpd when processing --------------------------------------------------------------------------------References: [ 1 ] Bug #1546008 - CVE-2018-5379 quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1546008 [ 2 ] Bug #1546006 - CVE-2018-5380 quagga: bgpd can overrun internal BGP code-to-string conversion tables potentially allowing crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1546006 [ 3 ] Bug #1546004 - CVE-2018-5381 quagga: Infinite loop issue triggered by invalid OPEN message allows denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1546004 [ 4 ] Bug #1546009 - CVE-2018-5378 quagga: bgpd does not properly bounds check the data sent with aNOTIFY allowing leak of sensitive data or crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1546009 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade quagga' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.