Publishing details

Changelog

quagga (1.2.4-4ubuntu0.4) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via out-of-bounds read
    - debian/patches/CVE-2022-37032.patch: don't memcpy past end of buffer
      in bgpd/bgp_packet.c.
    - CVE-2022-37032
  * SECURITY UPDATE: DoS via BGP UPDATE without mandatory attributes
    - debian/patches/CVE-2023-46753.patch: check mandatory attributes more
      carefully for UPDATE message in bgpd/bgp_attr.c.
    - CVE-2023-46753

 -- Marc Deslauriers <email address hidden>  Wed, 01 Nov 2023 14:49:20 -0400

Available diffs

Builds

Built packages

Package files