[zebra 22863] Zebra vulnerable to the recent Quagga security bugs, too?
Christian Hammers <[email protected]>
| Newsgroups | gmane.network.zebra |
|---|---|
| Message-ID | <[email protected]> |
Hello Three security problems have been reported against the Zebra fork Quagga (http://www.quagga.net) recently. They affect older parts of the code so it might be possible, that Zebra is also affected. As Debian shipped Zebra in version 0.92a with one of our releases we would like to know if there is the need for a security patch upload. You can read more about the bugs here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223 RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2224 RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2276 bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to cause a denial of service (CPU consumption) via a certain sh ip bgp command entered in the telnet interface. information (routing state) via REQUEST packets such as SEND UPDATE. Small patches for the individual problems can be found inside the Debian packages if you need them. thanks, -christian-