-
quagga (0.99.17-1ubuntu0.2) maverick-security; urgency=low
* SECURITY UPDATE: arbitrary code execution via malformed Inter Area
Prefix LSA
- debian/patches/99_CVE-2011-3323.dpatch: check lengths in
ospf6d/{ospf6_abr.h,ospf6_asbr.h,ospf6_intra.h,ospf6_lsa.h,
ospf6_message.c,ospf6_message.h,ospf6_proto.h}
- CVE-2011-3323
* SECURITY UPDATE: denial of sevice via crafted Link-State-Advertisement
- debian/patches/99_CVE-2011-3324.dpatch: change assert to warning in
ospf6d/ospf6_lsa.c.
- CVE-2011-3324
* SECURITY UPDATE: denial of service via crafted Hello packet
- debian/patches/99_CVE-2011-3325.dpatch: add extra checks to
ospfd/ospf_packet.c.
- CVE-2011-3325
* SECURITY UPDATE: denial of service via unknown Link-State-Advertisements
types
- debian/patches/99_CVE-2011-3326.dpatch: exit if LSA type is unknown
in ospfd/ospf_flood.c.
- CVE-2011-3326
* SECURITY UPDATE: arbitrary code execution via Extended Communities path
attribute
- debian/patches/99_CVE-2011-3327.dpatch: properly check size in
bgpd/bgp_ecommunity.c.
- CVE-2011-3327
-- Marc Deslauriers <email address hidden> Fri, 07 Oct 2011 10:19:05 -0400
-
quagga (0.99.17-1ubuntu0.1) maverick-security; urgency=low
* SECURITY UPDATE: denial of service via malformed extended communities
- debian/patches/99_quagga-extcom.dpatch: ignore malformed extended
communities in bgpd/bgp_attr.c.
- CVE-2010-1674
* SECURITY UPDATE: denial of service via AS_PATHLIMIT
- debian/patches/99_no-aspathlimit.dpatch: remove AS_PATHLIMIT support
in bgpd/bgp_attr.c.
- CVE-2010-1675
-- Marc Deslauriers <email address hidden> Wed, 23 Mar 2011 14:05:22 -0400
-
quagga (0.99.17-1) unstable; urgency=high
* SECURITY:
"This release provides two important bugfixes, which address remote crash
possibility in bgpd discovered by CROSS team.":
1. Stack buffer overflow by processing certain Route-Refresh messages
CVE-2010-2948
2. DoS (crash) while processing certain BGP update AS path messages
CVE-2010-2949
Closes: #594262
-- Michael Bienia <email address hidden> Mon, 06 Sep 2010 11:27:01 +0100
-
quagga (0.99.16-1) unstable; urgency=low
* New upstream release. Closes: #574527
* Added chrpath to debian/rules to fix rpath problems that lintian spottet.
quagga (0.99.15-2) unstable; urgency=low
* Applied patch for off-by-one bug in ospf6d that caused a segmentation
fault when using the "area a.b.c.d filter-list prefix" command (thanks
to Steinar H. Gunderson). Closes: 519488
-- Ubuntu Archive Auto-Sync <email address hidden> Sun, 09 May 2010 14:01:03 +0100
-
quagga (0.99.15-1) unstable; urgency=low
* New upstream release
"This fixes some annoying little ospfd and ospf6d regressions, which made
0.99.14 a bit of a problem release (...) This release still contains a
regression in the "no ip address ..." command, at least on Linux.
See bug #486, which contains a workaround patch. This release should be
considered a 1.0.0 release candidate. Please test this release as widely
as possible."
* Fixed wrong port number in zebra.8 (thanks to Thijs Kinkhorst).
Closes: #517860
* Added Russian Debconf tanslation (thanks to Yuri Kozlov).
Closes: #539464
* Removed so-version in build-dep to libreadline-dev on request of
Matthias Klose.
* Added README.source with reference to dpatch as suggested by lintian.
* Bumped standards versionto 3.8.3.
quagga (0.99.14-1) unstable; urgency=low
* New upstream release
"This release contains a regression fix for ospf6d, various small fixes
and some hopefully very significant bgpd stability fixes.
This release should be considered a 1.0.0 release candidate. Please test
this release as widely as possible."
* Fixes bug with premature LSA aging in ospf6d. Closes: #535030
* Fixes section number in zebra.8 manpage. Closes: #517860
quagga (0.99.13-2) unstable; urgency=low
* Added Japanese Debconf translation (thanks to Hideki Yamane).
Closes: #510714
* When checking for obsoleted config options in preinst, print filename
where it occures (thanks to Michael Bussmann). Closes: #339489
-- Ubuntu Archive Auto-Sync <email address hidden> Fri, 06 Nov 2009 10:32:48 +0000