Upgrade quagga in lucid

Bug #683958 reported by Michael Haro
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
quagga (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Medium
Unassigned
Hardy
Fix Released
Medium
Unassigned
Karmic
Fix Released
Medium
Unassigned
Lucid
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: quagga

The maverick chagelog says:

quagga (0.99.17-1) unstable; urgency=high

  * SECURITY:
    "This release provides two important bugfixes, which address remote crash
    possibility in bgpd discovered by CROSS team.":
    1. Stack buffer overflow by processing certain Route-Refresh messages
       CVE-2010-2948
    2. DoS (crash) while processing certain BGP update AS path messages
       CVE-2010-2949
    Closes: #594262

 -- Christian Hammers <email address hidden> Wed, 25 Aug 2010 00:52:48 +0200

Please upgrade the lucid package to resolve this security issue.

Thanks.

CVE References

Changed in quagga (Ubuntu):
status: New → Fix Released
Changed in quagga (Ubuntu Dapper):
status: New → Confirmed
Changed in quagga (Ubuntu Hardy):
status: New → Confirmed
Changed in quagga (Ubuntu Karmic):
status: New → Confirmed
Changed in quagga (Ubuntu Lucid):
status: New → Confirmed
Changed in quagga (Ubuntu Dapper):
importance: Undecided → Medium
Changed in quagga (Ubuntu Hardy):
importance: Undecided → Medium
Changed in quagga (Ubuntu Karmic):
importance: Undecided → Medium
Changed in quagga (Ubuntu Lucid):
importance: Undecided → Medium
visibility: private → public
Revision history for this message
Jamie Strandboge (jdstrand) wrote :
Changed in quagga (Ubuntu Lucid):
status: Confirmed → Fix Released
Changed in quagga (Ubuntu Dapper):
status: Confirmed → Fix Released
Changed in quagga (Ubuntu Hardy):
status: Confirmed → Fix Released
Changed in quagga (Ubuntu Karmic):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.