MGASA-2013-0310
Dashboard / Vulnerabilities / MGASA-2013-0310
Summary: Updated quagga packages fix CVE-2013-2236
Details: Updated quagga packages fix security vulnerability: Remotely exploitable buffer overflow in ospf_api.c and ospfclient.c when processing LSA messages in quagga before 0.99.22.2 (CVE-2013-2236). Note: We have worked around this vulnerability by disabling the ospf_api and ospfclient features, which did not provide useful functionality.
References: https://advisories.mageia.org/MGASA-2013-0310.html, http://lists.quagga.net/pipermail/quagga-dev/2013-July/010622.html, http://www.gentoo.org/security/en/glsa/glsa-201310-08.xml, https://bugs.mageia.org/show_bug.cgi?id=11433
Affected packages
Package
Name: quagga
Purl: pkg:rpm/mageia/quagga?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
