GLSA-200605-15 : Quagga Routing Suite: Multiple vulnerabilities

medium Nessus Plugin ID 21579

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200605-15 (Quagga Routing Suite: Multiple vulnerabilities)

Konstantin V. Gavrilenko discovered two flaws in the Routing Information Protocol (RIP) daemon that allow the processing of RIP v1 packets (carrying no authentication) even when the daemon is configured to use MD5 authentication or, in another case, even if RIP v1 is completely disabled. Additionally, Fredrik Widell reported that the Border Gateway Protocol (BGP) daemon contains a flaw that makes it lock up and use all available CPU when a specific command is issued from the telnet interface.
Impact :

By sending RIP v1 response packets, an unauthenticated attacker can alter the routing table of a router running Quagga's RIP daemon and disclose routing information. Additionally, it is possible to lock up the BGP daemon from the telnet interface.
Workaround :

There is no known workaround at this time.

Solution

All Quagga users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-misc/quagga-0.98.6-r1'

See Also

http://www.nessus.org/u?3ce7a319

https://security.gentoo.org/glsa/200605-15

Plugin Details

Severity: Medium

ID: 21579

File Name: gentoo_GLSA-200605-15.nasl

Version: 1.16

Type: local

Published: 5/22/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:quagga, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/21/2006

Reference Information

CVE: CVE-2006-2223, CVE-2006-2224, CVE-2006-2276

GLSA: 200605-15