RHSA-2012:1259: Moderate: quagga security update
Quagga is a TCP/IP based routing software suite. The Quagga bgpd daemonimplements the BGP (Border Gateway Protocol) routing protocol. The Quaggaospfd and ospf6d daemons implement the OSPF (Open Shortest Path First)routing protocol.A heap-based buffer overflow flaw was found in the way the bgpd daemonprocessed malformed Extended Communities path attributes. An attacker couldsend a specially-crafted BGP message, causing bgpd on a target system tocrash or, possibly, execute arbitrary code with the privileges of the userrunning bgpd. The UPDATE message would have to arrive from an explicitlyconfigured BGP peer, but could have originated elsewhere in the BGPnetwork. (CVE-2011-3327)A stack-based buffer overflow flaw was found in the way the ospf6d daemonprocessed malformed Link State Update packets. An OSPF router could usethis flaw to crash ospf6d on an adjacent router. (CVE-2011-3323)A flaw was found in the way the ospf6d daemon processed malformed linkstate advertisements. An OSPF neighbor could use this flaw to crashospf6d on a target system. (CVE-2011-3324)A flaw was found in the way the ospfd daemon processed malformed Hellopackets. An OSPF neighbor could use this flaw to crash ospfd on atarget system. (CVE-2011-3325)A flaw was found in the way the ospfd daemon processed malformed link stateadvertisements. An OSPF router in the autonomous system could use this flawto crash ospfd on a target system. (CVE-2011-3326)An assertion failure was found in the way the ospfd daemon processedcertain Link State Update packets. An OSPF router could use this flaw tocause ospfd on an adjacent router to abort. (CVE-2012-0249)A buffer overflow flaw was found in the way the ospfd daemon processedcertain Link State Update packets. An OSPF router could use this flaw tocrash ospfd on an adjacent router. (CVE-2012-0250)Two flaws were found in the way the bgpd daemon processed certain BGP OPENmessages. A configured BGP peer could cause bgpd on a target system toabort via a specially-crafted BGP OPEN message. (CVE-2012-0255,CVE-2012-1820)Red Hat would like to thank CERT-FI for reporting CVE-2011-3327,CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, and CVE-2011-3326; and theCERT/CC for reporting CVE-2012-0249, CVE-2012-0250, CVE-2012-0255, andCVE-2012-1820. CERT-FI acknowledges Riku Hietamäki, Tuomo Untinen and JukkaTaimisto of the Codenomicon CROSS project as the original reporters ofCVE-2011-3327, CVE-2011-3323, CVE-2011-3324, CVE-2011-3325, andCVE-2011-3326. The CERT/CC acknowledges Martin Winter atOpenSourceRouting.org as the original reporter of CVE-2012-0249,CVE-2012-0250, and CVE-2012-0255, and Denis Ovsienko as the originalreporter of CVE-2012-1820.Users of quagga should upgrade to these updated packages, which containbackported patches to correct these issues. After installing the updatedpackages, the bgpd, ospfd, and ospf6d daemons will be restartedautomatically.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2012:1259?
The severity of RHSA-2012:1259 is classified as important due to the potential for a heap-based buffer overflow.
How do I fix RHSA-2012:1259?
To fix RHSA-2012:1259, upgrade to quagga version 0.99.15-7.el6_3.2 or later.
What systems are affected by RHSA-2012:1259?
RHSA-2012:1259 affects multiple packages including quagga, quagga-devel, and quagga-contrib for Red Hat Enterprise Linux 6.
What kind of vulnerability does RHSA-2012:1259 address?
RHSA-2012:1259 addresses a heap-based buffer overflow vulnerability in the Quagga bgpd daemon.
Is there a workaround for RHSA-2012:1259?
There is no documented workaround for RHSA-2012:1259; the recommended action is to apply the security update.