[Bug 625740] [NEW] Sync quagga 0.99.17-1 (main) from Debian unstable (main)

Launchpad Bug Tracker 625740 at bugs.launchpad.net
Sat Aug 28 10:21:13 BST 2010


You have been subscribed to a public bug by Michael Bienia (geser):

Please sync quagga 0.99.17-1 (main) from Debian unstable (main)

A look at the upstream changelog
(http://www.quagga.net/download/quagga-0.99.17.changelog.txt)
shows no changes that would need a FFe. A look at the diffstat
of the debdiff shows also no huge changes to the source (except
generated files like configure and .in files).

Changelog entries since current maverick version 0.99.16-1:

quagga (0.99.17-1) unstable; urgency=high

  * SECURITY:
    "This release provides two important bugfixes, which address remote crash
    possibility in bgpd discovered by CROSS team.":
    1. Stack buffer overflow by processing certain Route-Refresh messages
       CVE-2010-2948
    2. DoS (crash) while processing certain BGP update AS path messages
       CVE-2010-2949
    Closes: #594262

 -- Christian Hammers <ch at debian.org>  Wed, 25 Aug 2010 00:52:48 +0200

** Affects: quagga (Ubuntu)
     Importance: Wishlist
         Status: Confirmed

-- 
Sync quagga 0.99.17-1 (main) from Debian unstable (main)
https://bugs.edge.launchpad.net/bugs/625740
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is a direct subscriber.



More information about the Ubuntu-sponsors mailing list