Release date:
Updated on: 2010-09-02
Affected Systems:
Quagga Routing Software Suite <0.99.17
Unaffected system:
Quagga Routing Software Suite 0.99.17
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42635
Cve id: CVE-2010-2948
Quagga is a route software suite that can implement multiple routing protocols on Unix platforms.
The bgpd daemon of Quagga has a stack overflow vulnerability when parsing a Route-Refresh message. The configured BGP peer can send a Route-Refresh message with a specially crafted read/write record to trigger this overflow, this causes bgpd to crash or execute arbitrary code.
<* Source: Chris Hall
Link: http://secunia.com/advisories/41038/
Http://permalink.gmane.org/gmane.comp.security.oss.general/3347
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 626783
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Quagga
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.quagga.net/news2.php? Y = 2010 & m = 8 & d = 19 # id1282241100