MGASA-2017-0416
Dashboard / Vulnerabilities / MGASA-2017-0416
Summary: Updated quagga packages fix security vulnerability
Details: The bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity (CVE-2017-16227).
References: https://advisories.mageia.org/MGASA-2017-0416.html, https://bugs.mageia.org/show_bug.cgi?id=21967, http://openwall.com/lists/oss-security/2017/10/30/4, https://www.debian.org/security/2017/dsa-4011, https://lists.quagga.net/pipermail/quagga-dev/2017-September/033284.html, http://git.savannah.gnu.org/cgit/quagga.git/commit/?id=7a42b78be9a4108d98833069a88e6fddb9285008
Affected packages
Package
Name: quagga
Purl: pkg:rpm/mageia/quagga?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
