[3.2] quagga: Buffer Overflow in IPv6 RA handling (CVE-2016-1245)
A buffer overflow exists in the IPv6 (Router Advertisement) code in
Zebra. The issue can be triggered on an IPv6
address where the Quagga daemon is reachable by a RA (Router
Advertisement or IPv6 ICMP message.
The issue leads to a crash of the zebra daemon. In specific
circumstances this vulnerability may allow remote code execution.
Fixed In Version:
Quagga 1.0.20161017
References:
https://lists.quagga.net/pipermail/quagga-users/2016-October/014478.html
http://www.gossamer-threads.com/lists/quagga/users/31952
Patch:
https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546
(from redmine: issue id 6384, created on 2016-10-25, closed on 2016-12-15)
- Relations:
- parent #6382 (closed)
- Changesets:
- Revision 8934a6fd by Sergei Lukin on 2016-12-13T14:05:06Z:
main/quagga: security upgrade - fixes #6384
CVE-2016-1245