Lucene search

K
redhatRedHatRHSA-2018:0377
HistoryFeb 28, 2018 - 4:24 p.m.

(RHSA-2018:0377) Important: quagga security update

2018-02-2816:24:10
access.redhat.com
67

0.056 Low

EPSS

Percentile

93.3%

The quagga packages contain Quagga, the free network-routing software suite that manages TCP/IP based protocols. Quagga supports the BGP4, BGP4+, OSPFv2, OSPFv3, RIPv1, RIPv2, and RIPng protocols, and is intended to be used as a Route Server and Route Reflector.

Security Fix(es):

  • quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code (CVE-2018-5379)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Red Hat would like to thank the Quagga project for reporting this issue.