Debian: zebra Denial of Service vulnerability
Summary
Two vulnerabilities were discovered in zebra, an IP routing daemon:
CAN-2003-0795 - a bug in the telnet CLI could allow a remote attacker
to cause a zebra process to crash, resulting in a denial of service.
CAN-2003-0858 - netlink messages sent by other users (rather than the
kernel) would be accepted, leading to a denial of service.
For the current stable distribution (woody) this problem has been
fixed in version 0.92a-5woody2.
The zebra package has been obsoleted in the unstable distribution by
GNU Quagga, where this problem was fixed in version 0.96.4x-4.
We recommend that you update your zebra package.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resou...