MGASA-2018-0133

Source
https://advisories.mageia.org/MGASA-2018-0133.html
Import Source
https://advisories.mageia.org/MGASA-2018-0133.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0133
Related
Published
2018-02-22T19:49:44Z
Modified
2026-02-04T04:16:31.705166Z
Summary
Updated quagga packages fix security vulnerability
Details

This is an update to fix several security issues. 1. CVE-2018-5379: Fix double free of unknown attribute 2. CVE-2018-5380: debug print of received NOTIFY data can over-read msg array 3. CVE-2018-5381: fix infinite loop on certain invalid OPEN messages

References
Credits

Affected packages

Mageia:6 / quagga

Package

Name
quagga
Purl
pkg:rpm/mageia/quagga?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.24.1-6.1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2018-0133.json"