Lucene search

K
cve[email protected]CVE-2003-0795
HistoryDec 15, 2003 - 5:00 a.m.

CVE-2003-0795

2003-12-1505:00:00
CWE-20
web.nvd.nist.gov
21
cve-2003-0795
quagga
zebra
telnet
security vulnerability
denial of service

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%

The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.

Affected configurations

NVD
Node
gnuzebraMatch0.91a
OR
gnuzebraMatch0.92a
OR
gnuzebraMatch0.93a
OR
gnuzebraMatch0.93b
OR
quaggaquaggaRange0.96.3
OR
quaggaquaggaMatch0.95
OR
quaggaquaggaMatch0.96
OR
quaggaquaggaMatch0.96.1
OR
quaggaquaggaMatch0.96.2
OR
sgipropackMatch2.2.1
OR
sgipropackMatch2.3

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%