* [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue
@ 2006-05-03 12:29 Michael Shigorin
2006-05-03 14:23 ` Sergey
0 siblings, 1 reply; 2+ messages in thread
From: Michael Shigorin @ 2006-05-03 12:29 UTC (permalink / raw)
To: sysadmins
Здравствуйте.
Кто там кваггу нахваливал? Чините.
----- Forwarded message from Secunia Security Advisories <sec-adv@secunia.com> -----
TITLE:
Quagga RIPd RIPv1 Request Handling Security Issue
SECUNIA ADVISORY ID:
SA19910
VERIFY ADVISORY:
http://secunia.com/advisories/19910/
CRITICAL:
Less critical
IMPACT:
Security Bypass, Exposure of system information
WHERE:
>From local network
SOFTWARE:
Quagga 0.x
http://secunia.com/product/4731/
DESCRIPTION:
Konstantin V. Gavrilenko has reported two security issues in Quagga,
which can be exploited by malicious people to bypass certain security
restrictions and to disclose system information.
1) An error in RIPd causes RIPv1 RESPONSE packets to be accepted for
routing state update, even when RIPv2 authentication has been
enabled. This can potentially be exploited to inject malicious route
into the RIP daemon.
2) An error in RIPd causes it to respond to RIPv1 SEND UPDATE
requests and to send out routing table information, even when RIPv2
authentication has been enabled. This can potentially be exploited to
obtain route information.
The security issues have been reported in 0.98.3 and 0.99.5. Other
versions may also be affected.
SOLUTION:
The security issues have been fixed in the CVS repositories.
PROVIDED AND/OR DISCOVERED BY:
Konstantin V. Gavrilenko
ORIGINAL ADVISORY:
http://bugzilla.quagga.net/show_bug.cgi?id=261
http://bugzilla.quagga.net/show_bug.cgi?id=262
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
----- End forwarded message -----
--
---- WBR, Michael Shigorin <mike@altlinux.ru>
------ Linux.Kiev http://www.linux.kiev.ua/
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue
2006-05-03 12:29 [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue Michael Shigorin
@ 2006-05-03 14:23 ` Sergey
0 siblings, 0 replies; 2+ messages in thread
From: Sergey @ 2006-05-03 14:23 UTC (permalink / raw)
To: sysadmins
On Wednesday 03 May 2006 17:29, Michael Shigorin wrote:
> Здравствуйте.
> Кто там кваггу нахваливал? Чините.
> ----- Forwarded message from Secunia Security Advisories <sec-adv@secunia.com> -----
>
> TITLE:
> Quagga RIPd RIPv1 Request Handling Security Issue
Вообще-то, оно достаточно старая часть. Неплохо бы и Зебру проверить...
Пересоберу сегодня/завтра из CVS.
--
С уважением, Сергей
a_s_y@sama.ru
PS: кстати, а, вообще, RIP кто-то ещё использует широко, интересно ?
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2006-05-03 14:23 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-05-03 12:29 [Sysadmins] Fwd: [SA19910] Quagga RIPd RIPv1 Request Handling Security Issue Michael Shigorin
2006-05-03 14:23 ` Sergey
ALT Linux sysadmins discussion
This inbox may be cloned and mirrored by anyone:
git clone --mirror http://lore.altlinux.org/sysadmins/0 sysadmins/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 sysadmins sysadmins/ http://lore.altlinux.org/sysadmins \
sysadmins@lists.altlinux.org sysadmins@lists.altlinux.ru sysadmins@lists.altlinux.com
public-inbox-index sysadmins
Example config snippet for mirrors.
Newsgroup available over NNTP:
nntp://lore.altlinux.org/org.altlinux.lists.sysadmins
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git