Updated quagga packages fix security vulnerability
Publication date: 26 Mar 2016Modification date: 26 Mar 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-2342
Description
A vulnerability was found in a way VPNv4 NLRI parser copied packet data to the stack. Memcpy to stack data structure based on length field from packet data whose length field upper-bound was not properly checked (CVE-2016-2342).
References
SRPMS
5/core
- quagga-0.99.22.4-4.1.mga5