Sync quagga 0.99.17-1 (main) from Debian unstable (main)

Bug #625740 reported by Michael Bienia
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
quagga (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync quagga 0.99.17-1 (main) from Debian unstable (main)

A look at the upstream changelog
(http://www.quagga.net/download/quagga-0.99.17.changelog.txt)
shows no changes that would need a FFe. A look at the diffstat
of the debdiff shows also no huge changes to the source (except
generated files like configure and .in files).

Changelog entries since current maverick version 0.99.16-1:

quagga (0.99.17-1) unstable; urgency=high

  * SECURITY:
    "This release provides two important bugfixes, which address remote crash
    possibility in bgpd discovered by CROSS team.":
    1. Stack buffer overflow by processing certain Route-Refresh messages
       CVE-2010-2948
    2. DoS (crash) while processing certain BGP update AS path messages
       CVE-2010-2949
    Closes: #594262

 -- Christian Hammers <email address hidden> Wed, 25 Aug 2010 00:52:48 +0200

CVE References

Michael Bienia (geser)
Changed in quagga (Ubuntu):
importance: Undecided → Wishlist
status: New → Confirmed
status: Confirmed → New
Revision history for this message
Thierry Carrez (ttx) wrote :

ACK

Changed in quagga (Ubuntu):
status: New → Confirmed
Revision history for this message
Colin Watson (cjwatson) wrote :

2010-09-06 10:26:59 INFO - <quagga_0.99.17.orig.tar.gz: downloading from http://ftp.debian.org/debian/>
[Updating] quagga (0.99.16-1 [Ubuntu] < 0.99.17-1 [Debian])
 * Trying to add quagga...
2010-09-06 10:27:00 INFO - <quagga_0.99.17-1.dsc: downloading from http://ftp.debian.org/debian/>
2010-09-06 10:27:00 INFO - <quagga_0.99.17-1.diff.gz: downloading from http://ftp.debian.org/debian/>
I: quagga [main] -> quagga_0.99.16-1 [main].
I: quagga [main] -> quagga-doc_0.99.16-1 [main].

Changed in quagga (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.