quagga 0.99.10-1lenny6 source package in Debian

Changelog

quagga (0.99.10-1lenny6) lenny-security; urgency=high


  * SECURITY:
    This is a backport of the security patches of Quagga 0.99.19 and 0.99.20:
    - The vulnerabilities CVE-2011-3324 and CVE-2011-3323 are related to the
      IPv6 routing protocol (OSPFv3) implemented in ospf6d daemon. Receiving
      modified Database Description and Link State Update messages,
      respectively, can result in denial of service in IPv6 routing.
    - The vulnerability CVE-2011-3325 is a denial of service vulnerability
      related to Hello message handling by the OSPF service. As Hello messages
      are used to initiate adjacencies, exploiting the vulnerability may be 
      feasible from the same broadcast domain without an established adjacency.
      A malformed packet may result in denial of service in IPv4 routing. 
    - The vulnerability CVE-2011-3326 results from the handling of LSA (Link 
      State Advertisement) states in the OSPF service. Receiving a modified
      Link State Update message with malicious state information can result in
      denial of service in IPv4 routing.
    - The vulnerability CVE-2011-3327 is related to the extended communities
      handling in BGP messages. Receiving a malformed BGP update can result in
      a buffer overflow and disruption of IPv4 routing.

 -- Florian Weimer <email address hidden>  Sun, 02 Oct 2011 14:28:25 +0200

Upload details

Uploaded by:
Christian Hammers
Uploaded to:
Lenny
Original maintainer:
Christian Hammers
Architectures:
any
Section:
net
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Lenny release main net

Builds

Downloads

File Size SHA-256 Checksum
quagga_0.99.10-1lenny6.dsc 1.6 KiB c960323156811fd9d4338511be7d05b55bffc848ac320e2abdb90353c477f001
quagga_0.99.10.orig.tar.gz 2.3 MiB f27d55904eb9a9eaf61a19b288ac79c9024b341734b984dccc04c343dfce890d
quagga_0.99.10-1lenny6.diff.gz 53.7 KiB 37d0289d05ed49ac7431997c6b29381e5035d88dc3af24a43bedde5cc574f90b

No changes file available.

Binary packages built by this source