[CLSA-2026:1777946639] quagga: Fix of CVE-2018-5381
Type:
security
Severity:
Important
Release date:
2026-05-05 02:04:04 UTC
Description:
- CVE-2018-5381: bgpd capability parser can enter an infinite loop on invalid OPEN messages whose Multi-Protocol capability has an unrecognized AFI/SAFI, causing a denial of service.
Updated packages:
  • quagga-0.99.15-14.0.2.el6.tuxcare.ol.els3.x86_64.rpm
    sha:f631b3bc117485ad1d02d8a7e8daf8efdb8ad4e1b4a4561182e3319fdd0c1e84
  • quagga-contrib-0.99.15-14.0.2.el6.tuxcare.ol.els3.x86_64.rpm
    sha:bb41d049a97d03338486ccb2faf02995d833d7eb9dd93313c21e18a9fba49962
  • quagga-devel-0.99.15-14.0.2.el6.tuxcare.ol.els3.i686.rpm
    sha:f31b7bf99022d0ef0d6a386f2085af505aa304f97a861c9958fed5e653ce1f05
  • quagga-devel-0.99.15-14.0.2.el6.tuxcare.ol.els3.x86_64.rpm
    sha:fa0eafce71dad1566e720a48bba3137e719f0f4ae207c7450b8d2c9a2b4f32e9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.