Oval Definition:oval:org.mitre.oval:def:22441
Revision Date:2014-05-26Version:13
Title:ELSA-2007:0389: quagga security update (Moderate)
Description:bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-1995
ELSA-2007:0389-02
Platform(s):Oracle Linux 5
Product(s):quagga
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • quagga-devel is earlier than 0:0.98.6-2.1.0.1.el5
  • OR quagga-contrib is earlier than 0:0.98.6-2.1.0.1.el5
  • OR quagga is earlier than 0:0.98.6-2.1.0.1.el5
  • BACK