RHEL 6 : quagga (RHSA-2017:0794)

critical Nessus Plugin ID 97885

Synopsis

The remote Red Hat host is missing one or more security updates for quagga.

Description

The remote Redhat Enterprise Linux 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2017:0794 advisory.

The quagga packages contain Quagga, the free network-routing software suite that manages TCP/IP based protocols. Quagga supports the BGP4, BGP4+, OSPFv2, OSPFv3, RIPv1, RIPv2, and RIPng protocols, and is intended to be used as a Route Server and Route Reflector.

Security Fix(es):

* A stack-based buffer overflow flaw was found in the way Quagga handled IPv6 router advertisement messages. A remote attacker could use this flaw to crash the zebra daemon resulting in denial of service.
(CVE-2016-1245)

* A stack-based buffer overflow flaw was found in the way the Quagga BGP routing daemon (bgpd) handled Labeled-VPN SAFI routes data. A remote attacker could use this flaw to crash the bgpd daemon resulting in denial of service. (CVE-2016-2342)

* A denial of service flaw was found in the Quagga BGP routing daemon (bgpd). Under certain circumstances, a remote attacker could send a crafted packet to crash the bgpd daemon resulting in denial of service.
(CVE-2016-4049)

* A denial of service flaw affecting various daemons in Quagga was found. A remote attacker could use this flaw to cause the various Quagga daemons, which expose their telnet interface, to crash. (CVE-2017-5495)

* A stack-based buffer overflow flaw was found in the way the Quagga OSPFD daemon handled LSA (link-state advertisement) packets. A remote attacker could use this flaw to crash the ospfd daemon resulting in denial of service. (CVE-2013-2236)

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL quagga package based on the guidance in RHSA-2017:0794.

See Also

http://www.nessus.org/u?c77be5c5

https://access.redhat.com/errata/RHSA-2017:0794

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=1316571

https://bugzilla.redhat.com/show_bug.cgi?id=1331372

https://bugzilla.redhat.com/show_bug.cgi?id=1386109

https://bugzilla.redhat.com/show_bug.cgi?id=1416013

https://bugzilla.redhat.com/show_bug.cgi?id=674862

https://bugzilla.redhat.com/show_bug.cgi?id=770731

https://bugzilla.redhat.com/show_bug.cgi?id=839620

https://bugzilla.redhat.com/show_bug.cgi?id=842308

https://bugzilla.redhat.com/show_bug.cgi?id=862826

https://bugzilla.redhat.com/show_bug.cgi?id=981124

Plugin Details

Severity: Critical

ID: 97885

File Name: redhat-RHSA-2017-0794.nasl

Version: 3.9

Type: local

Agent: unix

Published: 3/22/2017

Updated: 11/4/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2016-2342

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2016-1245

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:quagga, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:quagga-contrib, p-cpe:/a:redhat:enterprise_linux:quagga-devel

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 3/21/2017

Vulnerability Publication Date: 10/23/2013

Reference Information

CVE: CVE-2013-2236, CVE-2016-1245, CVE-2016-2342, CVE-2016-4049, CVE-2017-5495

CWE: 121, 770

RHSA: 2017:0794