[CLSA-2023:1697817200] quagga: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2023-10-20
Description:
- CVE-2023-41360: don't read the first byte of ORF header if we are ahead of stream - CVE-2023-41358: do not process NLRIs if the attribute length is zero
Updated packages:
  • quagga-0.99.15-14.el6.tuxcare.els2.x86_64.rpm
    sha:edfc8c6cd8d4c038851664c8ae966e588b2ca1bf
  • quagga-contrib-0.99.15-14.el6.tuxcare.els2.x86_64.rpm
    sha:bb719471f3f1c36e58f582038782e0d2a9c984de
  • quagga-devel-0.99.15-14.el6.tuxcare.els2.i686.rpm
    sha:2e7e7f3c0ec549f4ae42696ffeeb6543554ae89c
  • quagga-devel-0.99.15-14.el6.tuxcare.els2.x86_64.rpm
    sha:0a481bece123851dce30c0fd9db349d1207519b3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.