DSA-4011-1 quagga -- security update

Related Vulnerabilities: CVE-2017-16227  

It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity. For the oldstable distribution (jessie), this problem has been fixed in version 0.99.23.1-1+deb8u4. For the stable distribution (stretch), this problem has been fixed in version 1.1.1-3+deb9u1. We recommend that you upgrade your quagga packages.

Debian Security Advisory

DSA-4011-1 quagga -- security update

Date Reported:
30 Oct 2017
Affected Packages:
quagga
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 879474.
In Mitre's CVE dictionary: CVE-2017-16227.
More information:

It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity.

For the oldstable distribution (jessie), this problem has been fixed in version 0.99.23.1-1+deb8u4.

For the stable distribution (stretch), this problem has been fixed in version 1.1.1-3+deb9u1.

We recommend that you upgrade your quagga packages.