Vulnerability Bulletins

DSA-3532 quagga - security update

   
Affected software Debian
 
Kostya Kortchinsky discovered a stack-based buffer overflowvulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIProuting daemon. A remote attacker can exploit this flaw to cause adenial of service (daemon crash), or potentially, execution of arbitrarycode, if bgpd is configured with BGP peers enabled for VPNv4.

More info:

https://www.debian.org/security/2016/dsa-3532