LWN.net Logo

quagga: denial of service

Package(s):quagga CVE #(s):CVE-2012-1820
Created:June 19, 2012 Updated:April 10, 2013
Description: From the Red Hat bugzilla:

A denial of service flaw was found in the way Quagga's bgpd daemon processed certain OPEN messages. A configured Border Gateway Protocol (BGP) peer could send a BGP OPEN message with specially-crafted value of the Outbound Route Filtering (ORF) capability Type/Length/Value (TLV) triplet, which would cause the master BGP daemon (bgpd) to abort with an assertion failure by processing of such a message. Also, all BGP sessions established by the attacked router would be closed and its BGP routing disrupted.

Alerts:
Fedora FEDORA-2012-9103 2012-06-19
Fedora FEDORA-2012-9116 2012-06-19
Fedora FEDORA-2012-9117 2012-06-19
Debian DSA-2497-1 2012-06-20
Mageia MGASA-2012-0133 2012-06-27
Red Hat RHSA-2012:1259-01 2012-09-12
CentOS CESA-2012:1259 2012-09-12
Oracle ELSA-2012-1259 2012-09-13
Scientific Linux SL-quag-20120913 2012-09-13
Ubuntu USN-1605-1 2012-10-11
Mandriva MDVSA-2013:122 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds