LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Security Week: October 20th, 2014
Linux Advisory Watch: October 17th, 2014
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
RedHat: Moderate: quagga security update Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
RedHat Linux Updated quagga packages that fix several security vulnerabilities are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.
- ---------------------------------------------------------------------
                   Red Hat Security Advisory

Synopsis:          Moderate: quagga security update
Advisory ID:       RHSA-2006:0525-01
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2006-0525.html
Issue date:        2006-06-01
Updated on:        2006-06-01
Product:           Red Hat Enterprise Linux
CVE Names:         CVE-2006-2223 CVE-2006-2224 CVE-2006-2276 
- ---------------------------------------------------------------------

1. Summary:

Updated quagga packages that fix several security vulnerabilities are now
available.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Quagga manages the TCP/IP based routing protocol. It takes a multi-server
and multi-thread approach to resolve the current complexity of the Internet.

An information disclosure flaw was found in the way Quagga interprets RIP
REQUEST packets. RIPd in Quagga will respond to RIP REQUEST packets for RIP
versions that have been disabled or that have authentication enabled,
allowing a remote attacker to acquire information about the local network.
(CVE-2006-2223)

A route injection flaw was found in the way Quagga interprets RIPv1
RESPONSE packets when RIPv2 authentication is enabled. It is possible for a
remote attacker to inject arbitrary route information into the RIPd routing
tables. This issue does not affect Quagga configurations where only RIPv2
is specified. (CVE-2006-2224)

A denial of service flaw was found in Quagga's telnet interface. If an
attacker is able to connect to the Quagga telnet interface, it is possible
to cause Quagga to consume vast quantities of CPU resources by issuing a
malformed 'sh' command. (CVE-2006-2276)

Users of Quagga should upgrade to these updated packages, which contain
backported patches that correct these issues.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network.  To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

191080 - CVE-2006-2223 Quagga RIPd information disclosure
191084 - CVE-2006-2224 Quagga RIPd route injection
191376 - CVE-2006-2276 quagga locks with command sh ip bgp

6. RPMs required:

Red Hat Enterprise Linux AS version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/quagga-0.96.2-11.3E.src.rpm
fcd880dd2f1f922e8dc02160a947ec1d  quagga-0.96.2-11.3E.src.rpm

i386:
9161564a5722cb4bfe0ae7beb2b86057  quagga-0.96.2-11.3E.i386.rpm
34df55b9aab74f0dfa8dbb95318af308  quagga-debuginfo-0.96.2-11.3E.i386.rpm

ia64:
c44d0a382713b4c0af22df5c1caa6d26  quagga-0.96.2-11.3E.ia64.rpm
f8660048798bdc57c577b081fb1e39bb  quagga-debuginfo-0.96.2-11.3E.ia64.rpm

ppc:
22137d5727fe3fc6ec094c792735a6ac  quagga-0.96.2-11.3E.ppc.rpm
21a0593e16f0cb55f9ebcfdc431cd594  quagga-debuginfo-0.96.2-11.3E.ppc.rpm

s390:
6b9f107b9c8e403cc70084e644047d60  quagga-0.96.2-11.3E.s390.rpm
45316c7dc06db75489f8cf534fb76d25  quagga-debuginfo-0.96.2-11.3E.s390.rpm

s390x:
23524c23823e5b2c5c936be3f924a2ba  quagga-0.96.2-11.3E.s390x.rpm
4c22b6cd495766672968f874ad87a527  quagga-debuginfo-0.96.2-11.3E.s390x.rpm

x86_64:
8e752b034be7388f9487ccd502767699  quagga-0.96.2-11.3E.x86_64.rpm
5ce61ba937c19527617c9f2db2f817de  quagga-debuginfo-0.96.2-11.3E.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/quagga-0.96.2-11.3E.src.rpm
fcd880dd2f1f922e8dc02160a947ec1d  quagga-0.96.2-11.3E.src.rpm

i386:
9161564a5722cb4bfe0ae7beb2b86057  quagga-0.96.2-11.3E.i386.rpm
34df55b9aab74f0dfa8dbb95318af308  quagga-debuginfo-0.96.2-11.3E.i386.rpm

ia64:
c44d0a382713b4c0af22df5c1caa6d26  quagga-0.96.2-11.3E.ia64.rpm
f8660048798bdc57c577b081fb1e39bb  quagga-debuginfo-0.96.2-11.3E.ia64.rpm

x86_64:
8e752b034be7388f9487ccd502767699  quagga-0.96.2-11.3E.x86_64.rpm
5ce61ba937c19527617c9f2db2f817de  quagga-debuginfo-0.96.2-11.3E.x86_64.rpm

Red Hat Enterprise Linux AS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/quagga-0.98.3-2.4E.src.rpm
8e1e520295b2e60ec3a3a1456f4ac32c  quagga-0.98.3-2.4E.src.rpm

i386:
424c22075e47eaad5a39d1ffae6d12f0  quagga-0.98.3-2.4E.i386.rpm
ceb72b1d6d397937e95b265fe07506c2  quagga-contrib-0.98.3-2.4E.i386.rpm
4ea4f2364e99c7383304339d9369132b  quagga-debuginfo-0.98.3-2.4E.i386.rpm
2f723641cd3667ab3f71b3b037f3f1ee  quagga-devel-0.98.3-2.4E.i386.rpm

ia64:
772fcd0889d99758eef81559e2921c18  quagga-0.98.3-2.4E.ia64.rpm
240dbef8215983cace23e4ce75b17565  quagga-contrib-0.98.3-2.4E.ia64.rpm
b3342116d7fb8ab17cd60ef3bf13ef1c  quagga-debuginfo-0.98.3-2.4E.ia64.rpm
2ed5fa5bda76e0c12e8fb37a78eb1c24  quagga-devel-0.98.3-2.4E.ia64.rpm

ppc:
c5e07e8add5263b5d6fd48ca8f626f86  quagga-0.98.3-2.4E.ppc.rpm
23b66824e77246d0d66288c960d59e23  quagga-contrib-0.98.3-2.4E.ppc.rpm
18db7cc3db560be1606cff7285df7443  quagga-debuginfo-0.98.3-2.4E.ppc.rpm
08d3640a55e8c4324a3920f69520eaaa  quagga-devel-0.98.3-2.4E.ppc.rpm

s390:
046f86b73376db4020dbfb1e86035e68  quagga-0.98.3-2.4E.s390.rpm
9b98a6ede299736704f3d936f0b1d504  quagga-contrib-0.98.3-2.4E.s390.rpm
3ff1c0c9c283f58a8958859d4efadf2a  quagga-debuginfo-0.98.3-2.4E.s390.rpm
0219dc67fd0a6ce68f872d8e3e4a4414  quagga-devel-0.98.3-2.4E.s390.rpm

s390x:
9bf4e48db2b520bc6b961439d83a7a93  quagga-0.98.3-2.4E.s390x.rpm
9c063760f39f25aad41268d84053fe71  quagga-contrib-0.98.3-2.4E.s390x.rpm
33f8fb06581e74361664c1e7a5afdcbf  quagga-debuginfo-0.98.3-2.4E.s390x.rpm
a91489306834d2101f437082aa6204ad  quagga-devel-0.98.3-2.4E.s390x.rpm

x86_64:
3445db9b16c81b7949c292093447696e  quagga-0.98.3-2.4E.x86_64.rpm
b2e0ea7266db9aff12029cb12cfc5a59  quagga-contrib-0.98.3-2.4E.x86_64.rpm
38e49074ab20c380330ceaee2e243a94  quagga-debuginfo-0.98.3-2.4E.x86_64.rpm
2ea23e24a534bae762383d659b2ea250  quagga-devel-0.98.3-2.4E.x86_64.rpm

Red Hat Enterprise Linux Desktop version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/quagga-0.98.3-2.4E.src.rpm
8e1e520295b2e60ec3a3a1456f4ac32c  quagga-0.98.3-2.4E.src.rpm

i386:
424c22075e47eaad5a39d1ffae6d12f0  quagga-0.98.3-2.4E.i386.rpm
ceb72b1d6d397937e95b265fe07506c2  quagga-contrib-0.98.3-2.4E.i386.rpm
4ea4f2364e99c7383304339d9369132b  quagga-debuginfo-0.98.3-2.4E.i386.rpm
2f723641cd3667ab3f71b3b037f3f1ee  quagga-devel-0.98.3-2.4E.i386.rpm

x86_64:
3445db9b16c81b7949c292093447696e  quagga-0.98.3-2.4E.x86_64.rpm
b2e0ea7266db9aff12029cb12cfc5a59  quagga-contrib-0.98.3-2.4E.x86_64.rpm
38e49074ab20c380330ceaee2e243a94  quagga-debuginfo-0.98.3-2.4E.x86_64.rpm
2ea23e24a534bae762383d659b2ea250  quagga-devel-0.98.3-2.4E.x86_64.rpm

Red Hat Enterprise Linux ES version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/quagga-0.98.3-2.4E.src.rpm
8e1e520295b2e60ec3a3a1456f4ac32c  quagga-0.98.3-2.4E.src.rpm

i386:
424c22075e47eaad5a39d1ffae6d12f0  quagga-0.98.3-2.4E.i386.rpm
ceb72b1d6d397937e95b265fe07506c2  quagga-contrib-0.98.3-2.4E.i386.rpm
4ea4f2364e99c7383304339d9369132b  quagga-debuginfo-0.98.3-2.4E.i386.rpm
2f723641cd3667ab3f71b3b037f3f1ee  quagga-devel-0.98.3-2.4E.i386.rpm

ia64:
772fcd0889d99758eef81559e2921c18  quagga-0.98.3-2.4E.ia64.rpm
240dbef8215983cace23e4ce75b17565  quagga-contrib-0.98.3-2.4E.ia64.rpm
b3342116d7fb8ab17cd60ef3bf13ef1c  quagga-debuginfo-0.98.3-2.4E.ia64.rpm
2ed5fa5bda76e0c12e8fb37a78eb1c24  quagga-devel-0.98.3-2.4E.ia64.rpm

x86_64:
3445db9b16c81b7949c292093447696e  quagga-0.98.3-2.4E.x86_64.rpm
b2e0ea7266db9aff12029cb12cfc5a59  quagga-contrib-0.98.3-2.4E.x86_64.rpm
38e49074ab20c380330ceaee2e243a94  quagga-debuginfo-0.98.3-2.4E.x86_64.rpm
2ea23e24a534bae762383d659b2ea250  quagga-devel-0.98.3-2.4E.x86_64.rpm

Red Hat Enterprise Linux WS version 4:

SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/quagga-0.98.3-2.4E.src.rpm
8e1e520295b2e60ec3a3a1456f4ac32c  quagga-0.98.3-2.4E.src.rpm

i386:
424c22075e47eaad5a39d1ffae6d12f0  quagga-0.98.3-2.4E.i386.rpm
ceb72b1d6d397937e95b265fe07506c2  quagga-contrib-0.98.3-2.4E.i386.rpm
4ea4f2364e99c7383304339d9369132b  quagga-debuginfo-0.98.3-2.4E.i386.rpm
2f723641cd3667ab3f71b3b037f3f1ee  quagga-devel-0.98.3-2.4E.i386.rpm

ia64:
772fcd0889d99758eef81559e2921c18  quagga-0.98.3-2.4E.ia64.rpm
240dbef8215983cace23e4ce75b17565  quagga-contrib-0.98.3-2.4E.ia64.rpm
b3342116d7fb8ab17cd60ef3bf13ef1c  quagga-debuginfo-0.98.3-2.4E.ia64.rpm
2ed5fa5bda76e0c12e8fb37a78eb1c24  quagga-devel-0.98.3-2.4E.ia64.rpm

x86_64:
3445db9b16c81b7949c292093447696e  quagga-0.98.3-2.4E.x86_64.rpm
b2e0ea7266db9aff12029cb12cfc5a59  quagga-contrib-0.98.3-2.4E.x86_64.rpm
38e49074ab20c380330ceaee2e243a94  quagga-debuginfo-0.98.3-2.4E.x86_64.rpm
2ea23e24a534bae762383d659b2ea250  quagga-devel-0.98.3-2.4E.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2224
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2276
http://www.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is .  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2006 Red Hat, Inc.
 
< Prev   Next >
    
Partner

 

Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
USB is now UEC (use with extreme caution)
iPhone Encryption and the Return of the Crypto Wars
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2014 Guardian Digital, Inc. All rights reserved.