Summary
The remote host is missing an update to quagga
announced via advisory USN-775-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
quagga 0.99.2-1ubuntu3.5
Ubuntu 8.04 LTS:
quagga 0.99.9-2ubuntu1.2
Ubuntu 8.10:
quagga 0.99.9-6ubuntu0.1
Ubuntu 9.04:
quagga 0.99.11-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-775-1
Insight
It was discovered that the BGP service in Quagga did not correctly handle certain AS paths containing 4-byte ASNs. An authenticated remote attacker could exploit this flaw to cause bgpd to abort, leading to a denial of service.
Severity
Classification
-
CVE CVE-2009-1572 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities