CVE-2003-0795: Input Validation
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0795?
CVE-2003-0795 is classified as a denial of service vulnerability which can crash affected systems.
How do I fix CVE-2003-0795?
To fix CVE-2003-0795, you should upgrade to Quagga version 0.96.4 or later, or to a patched version of Zebra.
Which software is affected by CVE-2003-0795?
CVE-2003-0795 affects Quagga versions up to and including 0.96.3 and Zebra versions up to and including 0.93b.
What type of attack does CVE-2003-0795 enable?
CVE-2003-0795 allows remote attackers to perform a denial of service attack via malformed telnet commands.
Is CVE-2003-0795 remotely exploitable?
Yes, CVE-2003-0795 is remotely exploitable, allowing attackers to crash the service through network access.