Project

General

Profile

Bug #6384

Bug #6382: quagga: Buffer Overflow in IPv6 RA handling (CVE-2016-1245)

[3.2] quagga: Buffer Overflow in IPv6 RA handling (CVE-2016-1245)

Added by Alicha CH over 1 year ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Start date:
10/25/2016
Due date:
% Done:

100%

Estimated time:
Affected versions:

Description

A buffer overflow exists in the IPv6 (Router Advertisement) code in Zebra. The issue can be triggered on an IPv6
address where the Quagga daemon is reachable by a RA (Router Advertisement or IPv6 ICMP message.
The issue leads to a crash of the zebra daemon. In specific circumstances this vulnerability may allow remote code execution.

Fixed In Version:

Quagga 1.0.20161017

References:

https://lists.quagga.net/pipermail/quagga-users/2016-October/014478.html
http://www.gossamer-threads.com/lists/quagga/users/31952

Patch:

https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546

Associated revisions

Revision 8934a6fd (diff)
Added by Sergei Lukin over 1 year ago

main/quagga: security upgrade - fixes #6384

CVE-2016-1245

History

#1 Updated by Sergei Lukin over 1 year ago

  • Status changed from New to Resolved
  • % Done changed from 0 to 100

#2 Updated by Alicha CH over 1 year ago

  • Category set to Security
  • Status changed from Resolved to Closed

Also available in: Atom PDF