ELSA-2017-0794

ELSA-2017-0794 - quagga security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2017-03-27

Description


[0.99.15-14]
- Resolves: #1416013 - CVE-2017-5495 quagga: Telnet interface input buffer allocates unbounded amounts of memory

[0.99.15-13]
- fix path of ripd pid file (#842308)

[0.99.15-12]
- fix start() function in watchqugga initscript (#862826, #1208617)

[0.99.15-11]
- fix for CVE-2013-2236 (#1391918)
- fix for CVE-2016-1245 (#1391914)
- fix for CVE-2016-2342 (#1391916)
- fix for CVE-2016-4049 (#1391919)

[0.99.15-11]
- ospf6d: Fix crash when '[no] ipv6 ospf6 advertise prefix-list' is in startup-config (#770731)

[0.99.15-10]
- add watchquagga initscript (#862826, #1208617)
- remove pidfile when service is stopped (#842308)
- use QCONFDIR correctly in initscripts (#839620)
- include watchquagga and ospfclient manpages (#674862)

[0.99.15-9]
- improve fix for CVE-2011-3325

[0.99.15-8]
- fix CVE-2011-3323
- fix CVE-2011-3324
- fix CVE-2011-3325
- fix CVE-2011-3326
- fix CVE-2011-3327
- fix CVE-2012-0255
- fix CVE-2012-0249 and CVE-2012-0250
- fix CVE-2012-1820


Related CVEs


CVE-2013-2236
CVE-2016-2342
CVE-2017-5495
CVE-2016-1245
CVE-2016-4049

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) quagga-0.99.15-14.el6.src.rpm1e33cc2ab3108e75527a45d303c67cc2ELBA-2021-9020
quagga-0.99.15-14.el6.i686.rpmdd4c193239022464e4ded11a79ce1040ELBA-2021-9020
quagga-contrib-0.99.15-14.el6.i686.rpm83bda72d8b15497134c0e80011cc405eELBA-2021-9020
quagga-devel-0.99.15-14.el6.i686.rpma4e245a38787989bcd422c48d330391eELBA-2021-9020
Oracle Linux 6 (x86_64) quagga-0.99.15-14.el6.src.rpm1e33cc2ab3108e75527a45d303c67cc2ELBA-2021-9020
quagga-0.99.15-14.el6.x86_64.rpmafa340ab7400dd02cab21ef44314fa71ELBA-2021-9020
quagga-contrib-0.99.15-14.el6.x86_64.rpm8d6627384d7734eff12826c5284fdd2cELBA-2021-9020
quagga-devel-0.99.15-14.el6.i686.rpma4e245a38787989bcd422c48d330391eELBA-2021-9020
quagga-devel-0.99.15-14.el6.x86_64.rpm883233532ca163874ecb1eb33336939eELBA-2021-9020



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete