[Secure-testing-commits] r5640 - data/CVE

Florian Weimer fw at alioth.debian.org
Mon Apr 9 11:40:29 UTC 2007


Author: fw
Date: 2007-04-09 11:40:26 +0000 (Mon, 09 Apr 2007)
New Revision: 5640

Modified:
   data/CVE/list
Log:
quagga DoS


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2007-04-09 11:27:01 UTC (rev 5639)
+++ data/CVE/list	2007-04-09 11:40:26 UTC (rev 5640)
@@ -1,3 +1,8 @@
+CVE-2007-XXXX [Dos in quagga's bgpd through MP_REACH_NLRI and MP_UNREACH_NLRI]
+	- quagga <unfixed> (low; bug #418323)
+	NOTE: The attributes are non-transitive, which means that they
+	NOTE: are not propagated via BGP and therefore must originate
+	NOTE: from a peer (which is explicitly configured).
 CVE-2007-XXXX [initramfs-tools creates /dev/root world-readable]
 	- initramfs-tools 0.85g (low; bug #417995)
 CVE-2007-XXXX [dovecot zlib plugin directory traversal]




More information about the Secure-testing-commits mailing list