USN-7230-1: Quagga vulnerability
27 January 2025
Quagga could be made to crash if it received specially crafted network traffic.
Releases
Packages
- quagga - BGP/OSPF/RIP routing daemon
Details
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause Quagga
to crash, resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
quagga
-
1.2.4-1ubuntu0.1~esm2
Available with Ubuntu Pro
-
quagga-bgpd
-
1.2.4-1ubuntu0.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.