[quagga-users 6844] Re: Quagga RIPD unauthenticated route injection

Paul Jakma paul at clubi.ie
Thu May 4 17:47:49 IST 2006


On Thu, 4 May 2006, Paul Jakma wrote:

> See CVS for what is now 0.98.6-RC[1].

> http://hibernia.jakma.org/cgi-bin/gitweb.cgi?p=quagga.git;a=shortlog;h=quagga_0_98_stable

Oh, the 0.98.6-RC changelog, as can be seen above, is:

Security:

[ripd] bugs #261, #262: Fix RIPv1 info-leak and unauthenticated route updates
[ripd] 0.98 specific command changes, allow no-auth to be set
[bgpd] Fix infinite loop in community_str2com
[docs] Update ripd docs on version and authentication, see bugs #261,#262
[doc] Add test on 0.98 specific RIP authentication changes


Major bugfixes:

[bug #89] Fix leak of community when set community is used
[ospfd] Bug #234. Fix nbr_self reinitialisation after down/up.
[ospfd] Fix virtual-link handling in nbrs route-table, exposed by bug#234 fix
[ospfd] ignore loopbacks for received interface validation


Minor bugfixes:

[ospfd] Fix incorrect byte-order conversion of OSPF_MAX_SEQUENCE_NUMBER
[ospfd] fix rare leak of struct connected, in an error path.
[ospfd] Make database exchange for NSSA database work


Trivial fixes/enhancements:

[zebra] zebra_rib.c: Fix rib_delete_ipv6() to match routes in the RIB by
[0.98] Make "show ip ospf neighbor xxx" commands work.
[redhat] Update spec file with some changes from Fedora spec file
[lib] 'show route-map' should print call action seperate from exit policy
[ospfd] Fix failure of Fletcher checksum with certain compilers
[ospfd] fix undefined effect expression

regards,
-- 
Paul Jakma	paul at clubi.ie	paul at jakma.org	Key ID: 64A2FF6A
Fortune:
Cynic, n.:
 	Experienced.


More information about the Quagga-users mailing list