[CLSA-2023:1697817694] quagga: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2023-10-20
Description:
- CVE-2023-41360: don't read the first byte of ORF header if we are ahead of stream - CVE-2023-41358: do not process NLRIs if the attribute length is zero
Updated packages:
  • quagga-0.99.15-14.0.2.el6.tuxcare.ol.els2.x86_64.rpm
    sha:12328a9dc8e8f2865679d8dd4add1cc7463d0ce2
  • quagga-contrib-0.99.15-14.0.2.el6.tuxcare.ol.els2.x86_64.rpm
    sha:9444a76d4ddb55f5a997ef16bb620b34c9b529db
  • quagga-devel-0.99.15-14.0.2.el6.tuxcare.ol.els2.i686.rpm
    sha:898257ef06f4fdef01e2f43c3ab9ced24049828d
  • quagga-devel-0.99.15-14.0.2.el6.tuxcare.ol.els2.x86_64.rpm
    sha:ff84ae905c9eb1c5af63c4dc82bd0f292796c816
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.