3143511af8
Added CVE's to the changelog: CVE-2018-5378,Quagga-2018-0543,bsc#1079798 CVE-2018-5379,Quagga-2018-1114,bsc#1079799 CVE-2018-5380,Quagga-2018-1550,bsc#1079800 CVE-2018-5381,Quagga-2018-1975,bsc#1079801
Marius Tomaschewski2018-02-16 08:34:01 +00:00
7aa0fc88ae
- Applied security fix for bgpd DoS via specially crafted BGP UPDATE messages (CVE-2017-16227,bsc#1065641) [+ quagga-CVE-2017-16227-bgpd-Fix-AS_PATH-size-calculation.patch] - Applied security fix for bgpd bounds check issue via attribute length (Quagga-2018-0543,bsc#1079798) [+ Quagga-2018-0543-bgpd.bsc1079798.patch] - Applied security fix for bgpd double free when processing UPDATE message (Quagga-2018-1114,bsc#1079799) [+ Quagga-2018-1114-bgpd.bsc1079799.patch] - Applied security fix for bgpd code-to-string conversion tables overrun (Quagga-2018-1550,bsc#1079800) [+ Quagga-2018-1550-bgpd-bsc1079800.patch] - Applied security fix for bgpd infinite loop on certain invalid OPEN messages (Quagga-2018-1975,bsc#1079801) [+ Quagga-2018-1975-bdpd.bsc1079801.patch]
Marius Tomaschewski2018-02-16 08:18:18 +00:00
ac1d49b789
Accepting request 544669 from home:RBrownSUSE:branches:network
Dirk Mueller2017-11-24 10:22:19 +00:00
fb64044181
Accepting request 487325 from network
Yuchen Lin2017-04-12 15:37:33 +00:00
0eb49fbeb9
- Changed owner of /etc/quagga to quagga:quagga to permit to manage quagga via vty interface.
Marius Tomaschewski2017-04-11 12:10:01 +00:00
e183ef0ab6
- Disabled passwords in default zebra.conf config file, causing to disable vty telnet interface by default. The vty interface is available via "vtysh" utility using pam authentication to permit management access for root without password (bsc#1021669).
Marius Tomaschewski2017-04-11 12:00:55 +00:00
aef1de4876
Accepting request 485964 from network
Yuchen Lin2017-04-11 07:46:08 +00:00
dba8db6f0f
Accepting request 484850 from home:scarabeus_iv:branches:network
Dirk Mueller2017-04-06 05:38:56 +00:00
d25978b86a
- Added quagga.log and create and su statemets to logrotate config, changed default zebra log file name from quagga.log to zebra.log. - Cleaned up the spec file using spec-cleaner.
Marius Tomaschewski2017-03-31 07:36:00 +00:00
4180f7ba21
- Do not enable zebra's tcp interface (port 2600) to use default unix socket for communication between the daemons (fate#323170).
Marius Tomaschewski2017-03-29 11:55:37 +00:00
eb10580f3a
- Update to quagga-1.1.1, a security and bug fix release (fate#323168): See http://mirror.easyname.at/nongnu/quagga/quagga-1.1.1.changelog.txt for complete changelog, a digest of the changes: - Telnet 'vty' interface DoS fix due to unbounded memory allocation (CVE-2017-5495,bsc#1021669) - revert opsf6d: Update router-LSA when nbr's interface-ID changes See http://mirror.easyname.at/nongnu/quagga/quagga-1.0.20161017.changelog.txt for complete changelog, a digest of the changes: - isisd: Fix size of malloc - isisd: check for the existance of the correct list - ospf6d: fix off-by-one on display of spf reasons - ospf6d: don't access nexthops out of bounds - bgpd: fix off-by-one in attribute flags handling - zebra: stack overrun in IPv6 RA receive code (CVE-2016-1245) - bgpd: Fix buffer overflow error in bgp_dump_routes_func - Added libfpm_pb0 and libquagga_pb0 shared library sub-packages, adjusted libzebra0 sub-package name to libzebra1. - Use tmpfiles_create RPM macro to create quagga rundir and adjust tmpfiles config to contain proper rundir at install time. - Removed obsolete patches: quagga-CVE-2016-1245-stack-overrun-in-IPv6-RA-receive.patch quagga-CVE-2016-4049-fix-buf-ovflow-bgp-dump-routes.patch quagga-autoconf-detect-AM_SILENT_RULES.patch
Marius Tomaschewski2017-03-29 11:28:30 +00:00
b0beaef5f1
- Add quagga-CVE-2016-1245-stack-overrun-in-IPv6-RA-receive.patch: Fix for a zebra stack overrun in IPv6 RA receive code. (CVE-2016-1245, bsc#1005258)
Marius Tomaschewski2016-10-18 12:37:40 +00:00
8ab65b4430
- replace quagga.keyring with the newer upstream keyring.
Marcus Meissner2016-04-07 12:03:32 +00:00
cf114107de
- Add the %{_rundir} macro handling to spec in order to distinguish /run/ vs /var/run distro versions.
Pawel Wieczorkiewicz
2016-04-01 15:26:03 +00:00
620508aa47
- Update to 0.99.21 There are some major user-visible changes: [bgpd] BGP multipath support has been merged [bgpd] SAFI (Multicast topology) support has been extended to propagate the topology to zebra. [bgpd] AS path limit functionality has been removed [babeld] a new routing daemon implementing the BABEL ad-hoc mesh routing protocol has been merged. [isisd] a major overhaul has been picked up. Please note that isisd is STILL NOT SUITABLE FOR PRODUCTION USE. [*] a lot of bugs have been fixed, please refer to the git log The number of bugfixes and changes in this release is quite large at 446 commits, though some commits are counted twice due to a merge of Denis Ovsienko's RE branch some time ago. (Previous releases had around 50 commits each.) - additional changes from 0.99.20.1 This is a security-fix release that addresses 3 pending CVEs, one in bgpd and two in ospfd. The CVEs will be linked once released. - added quagga-0.99.21_isis_undefined_operations.patch: fix compiler warning about undefined operations - a47c5838e9f445ab887ad927706b11ccbb181364.patch Fix typo in isis topology code. Taken from git. - drop quagga-0.99.20-fix-bgpd-attr-memleak.patch: Included upstream - added options to build tcp-zebra, irdp and pcre: all enabled by default pcre change might cause problems in edge cases with bgp new buildrequires: pcre-devel - added option to build with isis and isis-topology: disabled by default
Marcus Rueckert2012-08-09 12:16:35 +00:00
f2f207574c
Accepting request 99287 from network
Stephan Kulow
2012-01-09 14:21:04 +00:00
07497a5499
- Update package to quagga-0.99.20, remove stale patches. added upstream patch to resolve a bgpd memleak
Pavol Rusnak
2012-01-06 16:50:11 +00:00
a177d5a9d2
replace license with spdx.org variant
Stephan Kulow
2011-12-06 17:59:14 +00:00
7d57e39a29
Updating link to change in openSUSE:Factory/quagga revision 33.0
OBS User buildservice-autocommit
2011-12-06 17:59:14 +00:00
fe10026524
Accepting request 93401 from network
Stephan Kulow
2011-11-25 10:13:38 +00:00
a18776ca6e
Accepting request 93368 from home:coolo:removelibtool
Marcus Meissner2011-11-24 11:11:03 +00:00
5441890a3c
Accepting request 87749 from network
Lars Vogdt
2011-10-16 10:56:46 +00:00
3d01fa17b7
Accepting request 87473 from home:yyyeer:branches:network
Lars Vogdt
2011-10-13 17:34:05 +00:00
60cd05abef
Autobuild autoformatter for 72573
Sascha Peilicke
2011-06-06 11:24:34 +00:00
9c64c38d8e
Updating link to change in openSUSE:Factory/quagga revision 29.0
OBS User buildservice-autocommit
2011-06-06 11:24:34 +00:00