Quagga: Denial of Service A vulnerability has been discovered in Quagga allowing for a Denial of Service. quagga May 02, 2007 May 02, 2007: 01 174206 remote 0.98.6-r2 0.98.6-r2

Quagga is a free routing daemon, supporting RIP, OSPF and BGP protocols.

The Quagga development team reported a vulnerability in the BGP routing deamon when processing NLRI attributes inside UPDATE messages.

A malicious peer inside a BGP area could send a specially crafted packet to a Quagga instance, possibly resulting in a crash of the Quagga daemon.

There is no known workaround at this time.

All Quagga users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/quagga-0.98.6-r2"
CVE-2007-1995 falco p-y p-y