[zebra 22863] Zebra vulnerable to the recent Quagga security bugs, too?

Christian Hammers <[email protected]>
Newsgroups gmane.network.zebra
Message-ID <[email protected]>
Hello

Three security problems have been reported against the Zebra fork Quagga
(http://www.quagga.net) recently. They affect older parts of the code so it
might be possible, that Zebra is also affected.

As Debian shipped Zebra in version 0.92a with one of our releases we would
like to know if there is the need for a security patch upload.

You can read more about the bugs here:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223
  RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement
  configurations that (1) disable RIPv1 or (2) require plaintext or MD5
  authentication, which allows remote attackers to obtain sensitive

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2224
  RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce
  RIPv2 authentication requirements, which allows remote attackers to
  modify routing state via RIPv1 RESPONSE packets.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2276
  bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to cause
  a denial of service (CPU consumption) via a certain sh ip bgp command
  entered in the telnet interface. information (routing state) via REQUEST
  packets such as SEND UPDATE. 
  
  Small patches for the individual problems can be found inside the Debian
  packages if you need them.
 
thanks,

 -christian-
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.