USN-6432-1: Quagga vulnerabilities
It was discovered that the Quagga BGP daemon did not properly check the attribute length in NRLI. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-41358) It was discovered that the Quagga BGP daemon did not properly manage memory when reading initial bytes of ORF header. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-41360)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Quagga vulnerability?
The vulnerability ID for this Quagga vulnerability is CVE-2023-41358.
What is the impact of the Quagga vulnerability CVE-2023-41358?
The impact of the Quagga vulnerability CVE-2023-41358 is a possible denial of service.
How can an attacker exploit the Quagga vulnerability CVE-2023-41358?
An attacker can exploit the Quagga vulnerability CVE-2023-41358 by manipulating attribute length in NRLI.
Which versions of Quagga are affected by this vulnerability?
Versions 1.2.4-4ubuntu0.1, 1.2.4-1ubuntu0.1~esm1, and 0.99.24.1-2ubuntu1.4+esm1 of Quagga are affected by this vulnerability.
How do I fix the Quagga vulnerability CVE-2023-41358?
To fix the Quagga vulnerability CVE-2023-41358, update Quagga to version 1.2.4-4ubuntu0.1 (for Ubuntu 20.04), version 1.2.4-1ubuntu0.1~esm1 (for Ubuntu 18.04), or version 0.99.24.1-2ubuntu1.4+esm1 (for Ubuntu 16.04).