First published: Tue Nov 18 2003(Updated: )
Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quagga Routing Software Suite | <=0.95 | |
GNU Zebra | <=0.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0858 is classified as a denial of service vulnerability.
To fix CVE-2003-0858, upgrade to Quagga version 0.95 or later, or GNU Zebra version 0.93b or later.
CVE-2003-0858 affects local users of Zebra 0.93b and earlier, as well as Quagga before version 0.95.
Systems running GNU Zebra or Quagga routing software, particularly versions below the specified updates, are impacted by CVE-2003-0858.
CVE-2003-0858 requires local user access to exploit, so it cannot be exploited remotely.