Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • aports aports
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Graph
    • Compare
  • Issues 660
    • Issues 660
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 352
    • Merge requests 352
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Releases
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • alpinealpine
  • aportsaports
  • Issues
  • #6385
Closed
Open
Issue created Oct 25, 2016 by Alicha CH@alichaReporter

[3.1] quagga: Buffer Overflow in IPv6 RA handling (CVE-2016-1245)

A buffer overflow exists in the IPv6 (Router Advertisement) code in Zebra. The issue can be triggered on an IPv6
address where the Quagga daemon is reachable by a RA (Router Advertisement or IPv6 ICMP message.
The issue leads to a crash of the zebra daemon. In specific circumstances this vulnerability may allow remote code execution.

Fixed In Version:

Quagga 1.0.20161017

References:

https://lists.quagga.net/pipermail/quagga-users/2016-October/014478.html
http://www.gossamer-threads.com/lists/quagga/users/31952

Patch:

https://github.com/Quagga/quagga/commit/cfb1fae25f8c092e0d17073eaf7bd428ce1cd546

(from redmine: issue id 6385, created on 2016-10-25, closed on 2016-12-15)

  • Relations:
    • parent #6382 (closed)
  • Changesets:
    • Revision f13612bb by Sergei Lukin on 2016-12-15T08:16:54Z:
main/quagga: security upgrade - fixes #6385

CVE-2016-1245
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking