drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in Quagga
| Name: |
Denial of Service in Quagga |
|
| ID: |
USN-7230-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 18.04 LTS |
|
| Datum: |
Di, 28. Januar 2025, 07:38 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-44070
https://ubuntu.com/security/notices/USN-7230-1 |
|
| Applikationen: |
quagga |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============2654887612527620921== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------nP5dwYgjIviXiLaBxw0hhkvx"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------nP5dwYgjIviXiLaBxw0hhkvx Content-Type: multipart/mixed; boundary="------------mvtu7XNMvV63391my5LaK6pU"; protected-headers="v1" From: John Breton <john.breton@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <03984b8c-24db-4af4-a46c-7d436fdeca5b@canonical.com> Subject: [USN-7230-1] Quagga vulnerability
--------------mvtu7XNMvV63391my5LaK6pU Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7230-1 January 27, 2025
quagga vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Quagga could be made to crash if it received specially crafted network traffic.
Software Description: - quagga: BGP/OSPF/RIP routing daemon
Details:
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04 LTS quagga 1.2.4-1ubuntu0.1~esm2 Available with Ubuntu Pro quagga-bgpd 1.2.4-1ubuntu0.1~esm2 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7230-1 CVE-2024-44070
--------------mvtu7XNMvV63391my5LaK6pU--
--------------nP5dwYgjIviXiLaBxw0hhkvx Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeYJ3QFAwAAAAAACgkQ8pSCVQZYHyhX 3g/9E4fAQJz7HlIQFtkUN8NQCElWna9NV6psI8ZyQvOCQGkQbgY56FO15HO49vcDC1VA2CM7hPlX REPfDRzZPF0rmA8tq364x9qrNM1ma/dlTZSvENXsFzbYifWw6kmWPfnl+z5Jge6vngL/OQh/G2MT ZaaWnJm5hRggqWetW017zh/1oVsWRUwFMbgdJwLhvy92PAtWHJvdwzRZbikcusfmW+QGeObB92dM xaTL3rFuUUKzGupXgm/29UP7GtGU7g3lUvbUy0wM9zPCnBrX51R+LgTK82hhNdeQxcyR0j7xYa8x 8DnowYa/XDPlQjLvIhzMV4+ZIctF8DqkgIQQx0ypAGf4hOClfcZDZF+GRwu0AJsIxdCC2qALZuDT DNMxg0pb3bhnRjG7GsMRyMX2tOeLuuNGiPk2smLqTVhtm3LvA51XpfQO7Mr3djXF2b6j8k+jQuzM 7dY8xsb5vbFvdUVBmzNZdPN/Ws8obL8f1RoL7ex1Xepsix5uVC84pgOavGaja7Ze96xmXOJR04V8 Ezp5GrLk5fY9i74I0u9DhUJRFTWNwgyl9+M6UqQySMVyzuB47XfJOHlksUOqrQwnOPl6vRVxqbth xDGpNuIwgSExg+SLL2LDBKnMciRPsAceqzhnxPMQFx94medgVrrIorJQ27pt/X8RwBUMc8tETMBd d3o= =1XVk -----END PGP SIGNATURE-----
--------------nP5dwYgjIviXiLaBxw0hhkvx--
--===============2654887612527620921== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============2654887612527620921==--
|
|
|
|