Oval Definition:oval:org.cisecurity:def:555
Revision Date:2016-07-01Version:6
Title:DSA-3532-1 -- quagga -- security update
Description:Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can exploit this flaw to cause a denial of service (daemon crash), or potentially, execution of arbitrary code, if bgpd is configured with BGP peers enabled for VPNv4.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-2342
DSA-3532-1
Platform(s):Debian 8
Debian GNU/kFreeBSD 7
Debian GNU/Linux 7
Product(s):quagga
Definition Synopsis
  • Debian 7
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND quagga is earlier than 0:0.99.22.4-1+wheezy2
  • OR Debian 8
  • Debian 8 is installed
  • AND quagga is earlier than 0:0.99.23.1-1+deb8u1
  • BACK