Release date:
Updated on:
Affected Systems:
Quagga Routing Software Suite <0.99.19
Unaffected system:
Quagga Routing Software Suite 0.99.19
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3325
Quagga is a network routing software package, which can realize OSPFv2, OSPFv3, RIP v1, v2, RIPng and BGP-4 on Unix, FreeBSD, Linux, Solaris, NetBSD and other platforms.
In the ospf_packet.c Implementation of ospf6d in Quagga versions earlier than 0.99.19, remote attackers can use the IPv4 packet header or the 0x0 a field in the intercepted IPv4 Hello packet to cause a denial of service.
<* Source: vendor
Link: http://www.kb.cert.org/vuls/id/668534
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Quagga
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.quagga.net/