Category Archives: Debian

Debian Security Advisories

DSA-3539 srtp – security update

Randell Jesup and the Firefox team discovered that srtp, Cisco’s
reference implementation of the Secure Real-time Transport Protocol
(SRTP), does not properly handle RTP header CSRC count and extension
header length. A remote attacker can exploit this vulnerability to crash
an application linked against libsrtp, resulting in a denial of service.

DSA-3533 openvswitch – security update

Kashyap Thimmaraju and Bhargava Shastry discovered a remotely
triggerable buffer overflow vulnerability in openvswitch, a production
quality, multilayer virtual switch implementation. Specially crafted
MPLS packets could overflow the buffer reserved for MPLS labels in an
OVS internal data structure. A remote attacker can take advantage of
this flaw to cause a denial of service, or potentially, execution of
arbitrary code.

DSA-3532 quagga – security update

Kostya Kortchinsky discovered a stack-based buffer overflow
vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP
routing daemon. A remote attacker can exploit this flaw to cause a
denial of service (daemon crash), or potentially, execution of arbitrary
code, if bgpd is configured with BGP peers enabled for VPNv4.