USN-7230-1: Quagga vulnerability
Published Jan 27, 2025
·Updated
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause Quagga to crash, resulting in a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/quagga<1.2.4-1ubuntu0.1~esm2
1.2.4-1ubuntu0.1~esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/quagga-bgpd<1.2.4-1ubuntu0.1~esm2
1.2.4-1ubuntu0.1~esm2
Ubuntu Ubuntu=18.04
Event History
Jan 27, 2025
Advisory Published
via Ubuntu·12:00 AM
Data Sourced
via Ubuntu·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of USN-7230-1?
The severity of USN-7230-1 is categorized as a denial of service vulnerability.
2
How do I fix USN-7230-1?
To fix USN-7230-1, you should update the Quagga package to version 1.2.4-1ubuntu0.1~esm2.
3
What software is affected by USN-7230-1?
USN-7230-1 affects the Quagga and Quagga-bgpd packages on Ubuntu 18.04.
4
Who discovered the vulnerability in USN-7230-1?
The vulnerability in USN-7230-1 was discovered by Iggy Frankovic.
5
Can USN-7230-1 be exploited remotely?
Yes, a remote attacker could exploit the vulnerability in USN-7230-1 to crash the Quagga service.