[3.1] quagga: Buffer Overflow in IPv6 RA handling (CVE-2016-1245)
A buffer overflow exists in the IPv6 (Router Advertisement) code in
Zebra. The issue can be triggered on an IPv6
address where the Quagga daemon is reachable by a RA (Router
Advertisement or IPv6 ICMP message.
The issue leads to a crash of the zebra daemon. In specific
circumstances this vulnerability may allow remote code execution.
Fixed In Version:
Quagga 1.0.20161017
References:
https://lists.quagga.net/pipermail/quagga-users/2016-October/014478.html
http://www.gossamer-threads.com/lists/quagga/users/31952
Patch:
https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546
(from redmine: issue id 6385, created on 2016-10-25, closed on 2016-12-15)
- Relations:
- parent #6382 (closed)
- Changesets:
- Revision f13612bb by Sergei Lukin on 2016-12-15T08:16:54Z:
main/quagga: security upgrade - fixes #6385
CVE-2016-1245