LWN.net Logo

quagga: multiple vulnerabilities

Package(s):quagga CVE #(s):CVE-2012-0249 CVE-2012-0250 CVE-2012-0255
Created:April 23, 2012 Updated:September 14, 2012
Description: From the CVE entries:

Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header. (CVE-2012-0249)

Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field. (CVE-2012-0250)

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability). (CVE-2012-0255)

Alerts:
Fedora FEDORA-2012-5411 2012-04-22
Fedora FEDORA-2012-5436 2012-04-22
Debian DSA-2459-1 2012-04-26
Debian DSA-2459-2 2012-05-04
Ubuntu USN-1441-1 2012-05-15
Red Hat RHSA-2012:1258-01 2012-09-12
Red Hat RHSA-2012:1259-01 2012-09-12
CentOS CESA-2012:1258 2012-09-12
CentOS CESA-2012:1259 2012-09-12
Oracle ELSA-2012-1258 2012-09-13
Oracle ELSA-2012-1259 2012-09-13
Scientific Linux SL-quag-20120913 2012-09-13
Scientific Linux SL-quag-20120913 2012-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds