Quagga: Multiple vulnerabilities Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code. quagga 2018-04-22 2018-04-22 647788 remote 1.2.4 1.2.4

Quagga is a free routing daemon replacing Zebra supporting RIP, OSPF and BGP.

Multiple vulnerabilities have been discovered in Quagga. Please review the CVE identifiers referenced below for details.

A remote attacker, by sending specially crafted packets, could execute arbitrary code or cause a Denial of Service condition.

There is no known workaround at this time.

All Quagga users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/quagga-1.2.4"
CVE-2018-5378 CVE-2018-5379 CVE-2018-5380 CVE-2018-5381 b-man b-man