Your message dated Thu, 28 Nov 2013 22:32:45 +0000
with message-id <e1vma8b-0004xa...@franck.debian.org>
and subject line Bug#726724: fixed in quagga 0.99.20.1-0+squeeze5
has caused the Debian Bug report #726724,
regarding quagga: CVE-2013-2236
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
726724: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726724
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: quagga
Severity: grave
Tags: security patch
Justification: user security hole

Hi Christian,
this was assigned CVE-2013-2236 some time ago, but apparently there was never a 
bug
filed for it:
http://lists.quagga.net/pipermail/quagga-dev/2013-July/010621.html

Fixed in 0.99.22.3:
http://nongnu.mirrors.hostinginnederland.nl//quagga/quagga-0.99.22.3.changelog.txt

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: quagga
Source-Version: 0.99.20.1-0+squeeze5

We believe that the bug you reported is fixed in the latest version of
quagga, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 726...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christian Hammers <c...@debian.org> (supplier of updated quagga package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 24 Nov 2013 15:41:48 +0100
Source: quagga
Binary: quagga quagga-dbg quagga-doc
Architecture: source amd64 all
Version: 0.99.20.1-0+squeeze5
Distribution: oldstable-security
Urgency: high
Maintainer: Christian Hammers <c...@debian.org>
Changed-By: Christian Hammers <c...@debian.org>
Description: 
 quagga     - BGP/OSPF/RIP routing daemon
 quagga-dbg - BGP/OSPF/RIP routing daemon (debug symbols)
 quagga-doc - documentation files for quagga
Closes: 726724
Changes: 
 quagga (0.99.20.1-0+squeeze5) oldstable-security; urgency=high
 .
   * SECURITY:
      ospfd: CVE-2013-2236, stack overrun in apiserver
 .
      the OSPF API-server (exporting the LSDB and allowing announcement of
      Opaque-LSAs) writes past the end of fixed on-stack buffers.  This leads
      to an exploitable stack overflow.
 .
      For this condition to occur, the following two conditions must be true:
      - Quagga is configured with --enable-opaque-lsa
      - ospfd is started with the "-a" command line option
      Closes: #726724
   * Re-upload with corrected distribution.
Checksums-Sha1: 
 1d27dd98eabd23c46c38dcebf924cad515209b66 1386 quagga_0.99.20.1-0+squeeze5.dsc
 01ff176591c8334736297dffc6a3082281cf85dc 40016 
quagga_0.99.20.1-0+squeeze5.debian.tar.gz
 790bd558f4d46d87c1b14ab82615a43ba8e8e908 1738638 
quagga_0.99.20.1-0+squeeze5_amd64.deb
 c886c5a87620c60cd23d920f195ae18e83243631 1749934 
quagga-dbg_0.99.20.1-0+squeeze5_amd64.deb
 eac70e94c04044bb9891f091b9d4e1aad41ea8c5 641800 
quagga-doc_0.99.20.1-0+squeeze5_all.deb
Checksums-Sha256: 
 95ac84cd02f7d51e8590477cde24944fdb4d3e17f364d104fe6d8f114e20871b 1386 
quagga_0.99.20.1-0+squeeze5.dsc
 872a260504691cba82c3fc8c7dc4c70081c6aa9a6bd7666a495465e69854d8e5 40016 
quagga_0.99.20.1-0+squeeze5.debian.tar.gz
 ce0dd5224733342664b596c32e61caa68d28cad0f84aa9362479d72eb90c6673 1738638 
quagga_0.99.20.1-0+squeeze5_amd64.deb
 338858fb0d2c87e58bf9857f0e711c989aeff5348d8439d824a02b32f5482d58 1749934 
quagga-dbg_0.99.20.1-0+squeeze5_amd64.deb
 f0a0e6624e51b2dcd7d3c45b0b836c54263ed8ef3db287f8fb08bb75e433ce7c 641800 
quagga-doc_0.99.20.1-0+squeeze5_all.deb
Files: 
 1bdce877d2658c9862bde184fdfdcc9a 1386 net optional 
quagga_0.99.20.1-0+squeeze5.dsc
 8bb7f8ed6c4ea5053ab44e545040c8ef 40016 net optional 
quagga_0.99.20.1-0+squeeze5.debian.tar.gz
 850afc8cb9a797191b517624c95fd8bd 1738638 net optional 
quagga_0.99.20.1-0+squeeze5_amd64.deb
 54549ee9db457ab498c57d51961e64f9 1749934 debug extra 
quagga-dbg_0.99.20.1-0+squeeze5_amd64.deb
 69cf316d74930ed5f14bdfd2ce682108 641800 net optional 
quagga-doc_0.99.20.1-0+squeeze5_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)

iEYEARECAAYFAlKSF8YACgkQkR9K5oahGObP1wCgqipw7pPKK0jVvWXYj+0tyf0/
VbYAn0XjlTMn0qTIt4fVvCZ7R2qJpVpQ
=90I2
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to