You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa bird

Sigurnosni nedostatak programskog paketa bird

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2019-ace80f492e
2019-09-20 01:21:28.248169
——————————————————————————–

Name : bird
Product : Fedora 30
Version : 2.0.6
Release : 1.fc30
URL : https://bird.network.cz/
Summary : BIRD Internet Routing Daemon
Description :
BIRD is a dynamic IP routing daemon supporting both, IPv4 and IPv6, Border
Gateway Protocol (BGPv4), Routing Information Protocol (RIPv2, RIPng), Open
Shortest Path First protocol (OSPFv2, OSPFv3), Babel Routing Protocol (Babel),
Bidirectional Forwarding Detection (BFD), IPv6 router advertisements, static
routes, inter-table protocol, command-line interface allowing on-line control
and inspection of the status of the daemon, soft reconfiguration as well as a
powerful language for route filtering.

——————————————————————————–
Update Information:

BIRD 2.0.6 (2019-09-10) ======================= * RAdv: Solicited unicast RAs
* BGP: Optional Adj-RIB-Out * BGP: Extended optional parameters length *
Filter: Sets and set expressions in path masks * Several important bugfixes
——————————————————————————–
ChangeLog:

* Wed Sep 11 2019 Robert Scheck <robert@fedoraproject.org> – 2.0.6-1
– Upgrade to 2.0.6 (#1751031, #1751349)
* Mon Aug 5 2019 Robert Scheck <robert@fedoraproject.org> – 2.0.5-1
– Upgrade to 2.0.5
* Wed Jul 24 2019 Fedora Release Engineering <releng@fedoraproject.org> – 2.0.4-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1751031 – CVE-2019-16159 bird: incorrect logical expressionwhen checking the validity of an input message leads to stack-based buffer overflow
https://bugzilla.redhat.com/show_bug.cgi?id=1751031
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-ace80f492e’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2019-b629e3b97f
2019-09-20 01:33:15.991438
——————————————————————————–

Name : bird
Product : Fedora 29
Version : 1.6.8
Release : 1.fc29
URL : https://bird.network.cz
Summary : BIRD Internet Routing Daemon
Description :
BIRD is a dynamic IP routing daemon supporting both, IPv4 and IPv6, Border
Gateway Protocol (BGPv4), Routing Information Protocol (RIPv2, RIPng), Open
Shortest Path First protocol (OSPFv2, OSPFv3), Babel Routing Protocol (Babel),
Bidirectional Forwarding Detection (BFD), IPv6 router advertisements, static
routes, inter-table protocol, command-line interface allowing on-line control
and inspection of the status of the daemon, soft reconfiguration as well as a
powerful language for route filtering.

This package contains IPv4 version.

——————————————————————————–
Update Information:

BIRD 1.6.8 (2019-09-10) ======================= * Several important bugfixes
——————————————————————————–
ChangeLog:

* Wed Sep 11 2019 Robert Scheck <robert@fedoraproject.org> – 1.6.8-1
– Upgrade to 1.6.8 (#1751031, #1751349)
* Mon Aug 5 2019 Robert Scheck <robert@fedoraproject.org> – 1.6.7-1
– Upgrade to 1.6.7
* Sat Mar 30 2019 Robert Scheck <robert@fedoraproject.org> – 1.6.6-1
– Upgrade to 1.6.6
* Fri Jan 18 2019 Robert Scheck <robert@fedoraproject.org> – 1.6.5-1
– Upgrade to 1.6.5
– Modernization and cleanup of spec file
– Ensure /etc/bird.conf can be only read by BIRD user
* Mon Nov 12 2018 Stanislav Kozina <skozina@redhat.org> – 1.6.4-2
– bird should run under bird user and group rather than root (#1397574)
– bird should run in foreground (#1285672)
* Mon Nov 12 2018 Stanislav Kozina <skozina@redhat.org> – 1.6.4-1
– Update bird to 1.6.4 (#1642737)
——————————————————————————–
References:

[ 1 ] Bug #1751031 – CVE-2019-16159 bird: incorrect logical expressionwhen checking the validity of an input message leads to stack-based buffer overflow
https://bugzilla.redhat.com/show_bug.cgi?id=1751031
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-b629e3b97f’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorZvonimir Bosnjak
Cert idNCERT-REF-2019-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa bird

Otkriven je sigurnosni nedostatak u programskom paketu bird za operacijski sustav Debian. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja...

Close