kumquat-buildroot/package/quagga
Peter Korsgaard 157a198d30 quagga: add upstream security fixes
Fixes the following security issues:

CVE-2018-5378

    It was discovered that the Quagga BGP daemon, bgpd, does not
    properly bounds check data sent with a NOTIFY to a peer, if an
    attribute length is invalid. A configured BGP peer can take
    advantage of this bug to read memory from the bgpd process or cause
    a denial of service (daemon crash).

    https://www.quagga.net/security/Quagga-2018-0543.txt

CVE-2018-5379

    It was discovered that the Quagga BGP daemon, bgpd, can double-free
    memory when processing certain forms of UPDATE message, containing
    cluster-list and/or unknown attributes, resulting in a denial of
    service (bgpd daemon crash).

    https://www.quagga.net/security/Quagga-2018-1114.txt

CVE-2018-5380

    It was discovered that the Quagga BGP daemon, bgpd, does not
    properly handle internal BGP code-to-string conversion tables.

    https://www.quagga.net/security/Quagga-2018-1550.txt

CVE-2018-5381

    It was discovered that the Quagga BGP daemon, bgpd, can enter an
    infinite loop if sent an invalid OPEN message by a configured peer.
    A configured peer can take advantage of this flaw to cause a denial
    of service (bgpd daemon not responding to any other events; BGP
    sessions will drop and not be reestablished; unresponsive CLI
    interface).

    https://www.quagga.net/security/Quagga-2018-1975.txt

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2018-02-19 23:48:35 +01:00
..
0001-fix-ipctl-forwarding.patch
0002-configure-fix-static-linking-with-readline.patch
0003-lib-memory-fix-indirect-static-link-with-zlib.patch
0004-bgpd-Fix-AS_PATH-size-calculation-for-long-paths.patch
0005-bgpd-security-invalid-attr-length-sends-NOTIFY-with-.patch
0006-bgpd-security-Fix-double-free-of-unknown-attribute.patch
0007-bgpd-security-debug-print-of-received-NOTIFY-data-ca.patch
0008-bgpd-security-fix-infinite-loop-on-certain-invalid-O.patch
Config.in
quagga_tmpfiles.conf
quagga.hash
quagga.mk
quagga@.service