ALT Linux sysadmins discussion
 help / color / mirror / Atom feed
* [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue
@ 2006-05-03 12:29 Michael Shigorin
  2006-05-03 14:23 ` Sergey
  0 siblings, 1 reply; 2+ messages in thread
From: Michael Shigorin @ 2006-05-03 12:29 UTC (permalink / raw)
  To: sysadmins

	Здравствуйте.
Кто там кваггу нахваливал?  Чините.

----- Forwarded message from Secunia Security Advisories <sec-adv@secunia.com> -----

TITLE:
Quagga RIPd RIPv1 Request Handling Security Issue

SECUNIA ADVISORY ID:
SA19910

VERIFY ADVISORY:
http://secunia.com/advisories/19910/

CRITICAL:
Less critical

IMPACT:
Security Bypass, Exposure of system information

WHERE:
>From local network

SOFTWARE:
Quagga 0.x
http://secunia.com/product/4731/

DESCRIPTION:
Konstantin V. Gavrilenko has reported two security issues in Quagga,
which can be exploited by malicious people to bypass certain security
restrictions and to disclose system information.

1) An error in RIPd causes RIPv1 RESPONSE packets to be accepted for
routing state update, even when RIPv2 authentication has been
enabled. This can potentially be exploited to inject malicious route
into the RIP daemon.

2) An error in RIPd causes it to respond to RIPv1 SEND UPDATE
requests and to send out routing table information, even when RIPv2
authentication has been enabled. This can potentially be exploited to
obtain route information.

The security issues have been reported in 0.98.3 and 0.99.5. Other
versions may also be affected.

SOLUTION:
The security issues have been fixed in the CVS repositories.

PROVIDED AND/OR DISCOVERED BY:
Konstantin V. Gavrilenko

ORIGINAL ADVISORY:
http://bugzilla.quagga.net/show_bug.cgi?id=261
http://bugzilla.quagga.net/show_bug.cgi?id=262

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

----- End forwarded message -----

-- 
 ---- WBR, Michael Shigorin <mike@altlinux.ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue
  2006-05-03 12:29 [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue Michael Shigorin
@ 2006-05-03 14:23 ` Sergey
  0 siblings, 0 replies; 2+ messages in thread
From: Sergey @ 2006-05-03 14:23 UTC (permalink / raw)
  To: sysadmins

On Wednesday 03 May 2006 17:29, Michael Shigorin wrote:

> 	Здравствуйте.
> Кто там кваггу нахваливал?  Чините.

> ----- Forwarded message from Secunia Security Advisories <sec-adv@secunia.com> -----
> 
> TITLE:
> Quagga RIPd RIPv1 Request Handling Security Issue

Вообще-то, оно достаточно старая часть. Неплохо бы и Зебру проверить...
Пересоберу сегодня/завтра из CVS.

-- 
С уважением, Сергей
a_s_y@sama.ru

PS: кстати, а, вообще, RIP кто-то ещё использует широко, интересно ?


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-05-03 14:23 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-05-03 12:29 [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue Michael Shigorin
2006-05-03 14:23 ` Sergey

ALT Linux sysadmins discussion

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://lore.altlinux.org/sysadmins/0 sysadmins/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 sysadmins sysadmins/ http://lore.altlinux.org/sysadmins \
		sysadmins@lists.altlinux.org sysadmins@lists.altlinux.ru sysadmins@lists.altlinux.com
	public-inbox-index sysadmins

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://lore.altlinux.org/org.altlinux.lists.sysadmins


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git