Otkriveno je više sigurnosnih propusta u radu programskog paketa Quagga. Moguće ih je iskoristiti udaljeno, za izvođenje napada uskraćivanjem usluge (DoS).
Paket:
quagga 0.x
Operacijski sustavi:
CentOS
Kritičnost:
6.5
Problem:
pogreška u programskoj funkciji, pogreška u programskoj komponenti, preljev međuspremnika
Propusti su uzrokovani pogreškama u funkcijama "ospf6_lsa_is_changed", "ospf_flood", nepravilnošću u implementaciji OSPFv3, prepisivanjem spremnika u funkcijama "ecommunity_ecom2str" i "ospf_ls_upd_list_lsa", itd. Za uvid u sve propuste preporuča se pregled teksta izvorne preporuke.
Posljedica:
Napadačima omogućuju izvođenje DoS (eng. Denial of Service) napada.
Rješenje:
Korisnicima se savjetuje instalacija sigurnosnih zakrpa.
CentOS Errata and Security Advisory 2012:1259 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1259.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
3c6e15ef1b49d41a5998c59e0ed1269c0e8a4847190e376528860de8114e1fa8
quagga-0.99.15-7.el6_3.2.i686.rpm
a1df0a8bc7151c943ad92f0dbc33397b14bbf5c11efe00d5c2ca0b5096ccbd63
quagga-contrib-0.99.15-7.el6_3.2.i686.rpm
0c4f326e942640131b7a6aa287eeb7dea5acaddcda31fa18457b7f7dc2200b85
quagga-devel-0.99.15-7.el6_3.2.i686.rpm
x86_64:
156485158bd3aac2f8e4b69f6429acb245e1bc0b61781d5ebe6b3b90c069a5b5
quagga-0.99.15-7.el6_3.2.x86_64.rpm
3fa918852c1e72985fa0141b64e66c407965cd9a482627fdaf38a3f550de13fd
quagga-contrib-0.99.15-7.el6_3.2.x86_64.rpm
0c4f326e942640131b7a6aa287eeb7dea5acaddcda31fa18457b7f7dc2200b85
quagga-devel-0.99.15-7.el6_3.2.i686.rpm
2171387bcf44850288bd4d034352d11613130d9a293750234cb5326533c75199
quagga-devel-0.99.15-7.el6_3.2.x86_64.rpm
Source:
e67c6b02f26da4c6c9e0b79ea8288e1ee495ed1c5b31ea78ff8b1e2644a62b94
quagga-0.99.15-7.el6_3.2.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2012:1258 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1258.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
9e44ffefa5dd2c51c5671edc8f39b336d2ac6230025e8dd3e2f7411ea9f233e9
quagga-0.98.6-7.el5_8.1.i386.rpm
e220b0c56c1e15755ea5e793bc2f4b7054cc7c9e030578941d62ab685fa3d6b2
quagga-contrib-0.98.6-7.el5_8.1.i386.rpm
0fd7b63c30861fcc848011e0c06ce1d1fae86806bfddccb093edeecd3b9e750f
quagga-devel-0.98.6-7.el5_8.1.i386.rpm
x86_64:
abfe7f485a4cf7fb01875abc123d9e4db3da54bc3f40af5d2dd7568e2fe102fd
quagga-0.98.6-7.el5_8.1.x86_64.rpm
73b805cd5d4c301bd55fc703f13685b1262864afd185a440a9881b4370c669ab
quagga-contrib-0.98.6-7.el5_8.1.x86_64.rpm
0fd7b63c30861fcc848011e0c06ce1d1fae86806bfddccb093edeecd3b9e750f
quagga-devel-0.98.6-7.el5_8.1.i386.rpm
590b6983926d2a29dcc770300183079dbf9ac494b5be182923bd07ba5aae3821
quagga-devel-0.98.6-7.el5_8.1.x86_64.rpm
Source:
44589f3fd9bac0b0e87f2ae808cfe6dcfec1c6460f095561d7be2fefc71d9041
quagga-0.98.6-7.el5_8.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke