MGASA-2016-0165
Dashboard / Vulnerabilities / MGASA-2016-0165
Summary: Updated quagga packages fix CVE-2016-4049
Details: Updated quagga packages fix security vulnerability: A denial of dervice vulnerability have been found in BGP daemon from Quagga routing software (bgpd): if the following conditions are satisfied: - regular dumping is enabled - bgpd instance has many BGP peers then BGP message packets that are big enough cause bgpd to crash. The situation when the conditions above are satisfied is quite common. Moreover, it is easy to craft a packet which is much "bigger" than a typical packet, and hence such crafted packet can much more likely cause the crash (CVE-2016-4049).
References: https://advisories.mageia.org/MGASA-2016-0165.html, https://bugs.mageia.org/show_bug.cgi?id=18280, http://openwall.com/lists/oss-security/2016/04/27/7
Affected packages
Package
Name: quagga
Purl: pkg:rpm/mageia/quagga?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
