USN-7017-1: Quagga vulnerability
Published Sep 17, 2024
·Updated
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/quagga<1.2.4-4ubuntu0.5
1.2.4-4ubuntu0.5
Ubuntu Ubuntu=20.04
All of the following
ubuntu/quagga-bgpd<1.2.4-4ubuntu0.5
1.2.4-4ubuntu0.5
Ubuntu Ubuntu=20.04
Event History
Sep 17, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7017-1?
USN-7017-1 is considered critical as it can lead to a denial of service by crashing the Quagga application.
2
How do I fix USN-7017-1?
To fix USN-7017-1, you should upgrade to Quagga version 1.2.4-4ubuntu0.5 or later.
3
Which versions of Quagga are affected by USN-7017-1?
USN-7017-1 affects Quagga versions prior to 1.2.4-4ubuntu0.5 on Ubuntu 20.04.
4
What issues does USN-7017-1 address in Quagga?
USN-7017-1 addresses a vulnerability in Quagga's handling of certain BGP messages that may lead to application crashes.
5
Who discovered the vulnerability in USN-7017-1?
The vulnerability addressed in USN-7017-1 was discovered by Iggy Frankovic.