oval:org.mitre.oval:def:12727
Definition Id: oval:org.mitre.oval:def:12727 | |||
Oval ID: | oval:org.mitre.oval:def:12727 | ||
Title: | DSA-2104-1 quagga -- several | ||
Description: | Several remote vulnerabilities have been discovered in the BGP implementation of Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-2948 When processing a crafted Route Refresh message received from a configured, authenticated BGP neighbor, Quagga may crash, leading to a denial of service. CVE-2010-2949 When processing certain crafted AS paths, Quagga would crash with a NULL pointer dereference, leading to a denial of service. In some configurations, such crafted AS paths could be relayed by intermediate BGP routers. In addition, this update contains a reliability fix: Quagga will no longer advertise confederation-related AS paths to non-confederation peers, and reject unexpected confederation-related AS paths by resetting the session with the BGP peer which is advertising them. For the stable distribution, these problems have been fixed in version 0.99.10-1lenny3. For the unstable distribution and the testing distribution, these problems have been fixed in version 0.99.17-1. We recommend that you upgrade your quagga package. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2104-1 CVE-2010-2948 CVE-2010-2949 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | quagga |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6513 | |||
Oval ID: | oval:org.mitre.oval:def:6513 | ||
Title: | Debian GNU/Linux 5.0 is installed | ||
Description: | Debian GNU/Linux 5.0 (lenny) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux:5.0 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12727 |