quagga 0.99.17-2+squeeze3 source package in Debian

Changelog

quagga (0.99.17-2+squeeze3) stable-security; urgency=high


  * SECURITY:
    This is a backport of the security patches of Quagga 0.99.19 and 0.99.20:
    - The vulnerabilities CVE-2011-3324 and CVE-2011-3323 are related to the
      IPv6 routing protocol (OSPFv3) implemented in ospf6d daemon. Receiving
      modified Database Description and Link State Update messages,
      respectively, can result in denial of service in IPv6 routing.
    - The vulnerability CVE-2011-3325 is a denial of service vulnerability
      related to Hello message handling by the OSPF service. As Hello messages
      are used to initiate adjacencies, exploiting the vulnerability may be 
      feasible from the same broadcast domain without an established adjacency.
      A malformed packet may result in denial of service in IPv4 routing. 
    - The vulnerability CVE-2011-3326 results from the handling of LSA (Link 
      State Advertisement) states in the OSPF service. Receiving a modified
      Link State Update message with malicious state information can result in
      denial of service in IPv4 routing.
    - The vulnerability CVE-2011-3327 is related to the extended communities
      handling in BGP messages. Receiving a malformed BGP update can result in
      a buffer overflow and disruption of IPv4 routing.

 -- Christian Hammers <email address hidden>  Sun, 02 Oct 2011 01:00:22 +0200

Upload details

Uploaded by:
Christian Hammers
Uploaded to:
Squeeze
Original maintainer:
Christian Hammers
Architectures:
any
Section:
net
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
quagga_0.99.17-2+squeeze3.dsc 1.6 KiB dcc3eaa9500b4741d0f86920f1b1fd8d144ff4fb447892f9d52ddc35a766f312
quagga_0.99.17.orig.tar.gz 2.1 MiB 1d77df121a334e9504b45e489ee7ce35bf478e27d33cd2793a23280b59d9efd4
quagga_0.99.17-2+squeeze3.diff.gz 46.2 KiB 4f21dc046accfad851685ef9d3d9dd2f465cca999f15af91523224cda614d644

No changes file available.

Binary packages built by this source