Debian Security Advisory
DSA-4011-1 quagga -- security update
- Date Reported:
- 30 Oct 2017
- Affected Packages:
- quagga
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 879474.
In Mitre's CVE dictionary: CVE-2017-16227. - More information:
-
It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity.
For the oldstable distribution (jessie), this problem has been fixed in version 0.99.23.1-1+deb8u4.
For the stable distribution (stretch), this problem has been fixed in version 1.1.1-3+deb9u1.
We recommend that you upgrade your quagga packages.